Last updated: March 2026
Webhooks allow you to build or set up integrations that subscribe to certain events on MyLinkHub. When one of those events is triggered, we send an HTTP POST payload to your configured URL. Webhooks can update an external CRM, trigger automations, or sync analytics data.
Each webhook event delivers a JSON payload containing the event type, a unique identifier, a timestamp, and event-specific data.
{
"eventId": "evt_2d4b9f8a3c1...",
"event": "link.clicked",
"timestamp": "2024-03-21T10:30:00.000Z",
"data": {
"linkId": "link_123",
"url": "https://example.com/promo",
"visitor": {
"ip": "192.168.1.1",
"userAgent": "Mozilla/5.0..."
}
}
}Triggered whenever a visitor clicks on one of the links on your MyLinkHub profile.
Triggered whenever a visitor opens your MyLinkHub profile page.
Triggered when a user successfully submits their email or phone number in a lead capture block.
MyLinkHub signs all webhook events using a cryptographic signature so you can verify that requests legitimately originate from us. We include an X-MyLinkHub-Signature header with every request.
The signature is an HMAC-SHA256 hash of the raw JSON request body, signed using your unique Webhook Secret.
const crypto = require('crypto');
function verifyWebhook(payloadString, signatureHeader, secret) {
const expectedSignature = crypto
.createHmac('sha256', secret)
.update(payloadString)
.digest('hex');
// Use a constant-time comparison to prevent timing attacks
return crypto.timingSafeEqual(
Buffer.from(signatureHeader),
Buffer.from(expectedSignature)
);
}If your endpoint requires authentication (such as a Bearer token or custom API key), you can configure headers directly in your webhook settings. MyLinkHub attaches these headers to every delivery request alongside our HMAC signature.