Skip to main content
Receive HTTP callbacks from external services (Stripe, GitHub, Twilio, etc.) by creating routes matching /api/webhook/* and turning on Webhook Access in your app’s settings. When enabled, only /api/webhook/* routes are publicly accessible - all other routes remain protected.
If you want an external event to start work in Major, use a webhook trigger instead. Webhook triggers start a workflow and every call is authenticated with a credential, so they are the more secure and preferred option. Use webhook routes only when a service must post raw payloads to your app and can’t send a credential.

Setup

Create an API route in your app under the /api/webhook/ path:

Security

Best practice is to verify webhook signatures to ensure requests come from the expected source. Most services (Stripe, GitHub, etc.) include a signature header that you can validate against a shared secret.