Webhook
A URL that starts the workflow. For everything that can send an HTTP request and is not one of the named triggers.
Run when an HTTP request hits a generated webhook URL.
Reach for it when
- A build system, a cron box, or a script of your own that needs to kick off a device run.
- Wiring up a service this app has no dedicated trigger for.
Every setting this block has. A field marked only when appears once you have chosen the mode above it — those are alternatives to each other, not extra things to fill in.
- Methodstarts at POST
A request using the other method reaches the endpoint but doesn't start a run.
POSTGET - DevicesRequiredstarts at —
Which devices this trigger runs on.
- Run across devicesstarts at Sequential — one device at a timeSequential — one device at a timeParallel — all at once
- Stop the run afterstarts at 15
Minutes of device time this run may hold before it is stopped, counted across every device it uses. A run nobody is watching cannot be told to stop, and a phone waits on a selector that will never match for as long as it is allowed to.
Pick the method you will send
A request using the other method still reaches the endpoint — it simply does not start a run. That keeps a health check from burning device minutes.
WebhookSettings MethodGET or POSTPOSTSend the shared secret with the request
Either header works. There is no signature here because the sender is unknown — a shared secret is what a generic caller can manage.
the request you send - POST…/api/hooks/<token>
- X-Remonode-Secret••••••••••
- or AuthorizationBearer ••••••
What the endpoint does with it
somewhere elseyour script · POST/api/hooks/…- the shared secret matches
- the method matches the field above
- a graph that waits for a person is refused — nobody answers at 4am
- at most one run per endpoint every 30 seconds
queued — 2 devices
- A queued run per accepted request, on the devices this trigger names.
- An unknown token and a disabled one both answer 404, identically. Telling them apart would turn the endpoint into a way to find valid tokens.
- Anyone holding the URL and the secret can spend your device minutes. Rotate replaces both.
- Running without a person needs the Starter plan — that covers a schedule and the endpoint an event trigger listens on. Run once still works on Free.