← Node guide
Triggers

Webhook

A URL that starts the workflow. For everything that can send an HTTP request and is not one of the named triggers.

start.webhookStarts the workflow
The piece

Run when an HTTP request hits a generated webhook URL.

Reach for it when

  • A build system, a cron box, or a script of your own that needs to kick off a device run.
  • Wiring up a service this app has no dedicated trigger for.
Webhook
1 deviceIdle
In the bag

Every setting this block has. A field marked only when appears once you have chosen the mode above it — those are alternatives to each other, not extra things to fill in.

  • Method
    starts at POST

    A request using the other method reaches the endpoint but doesn't start a run.

    POSTGET
  • DevicesRequired
    starts at —

    Which devices this trigger runs on.

  • Run across devices
    starts at Sequential — one device at a time
    Sequential — one device at a timeParallel — all at once
  • Stop the run after
    starts at 15

    Minutes of device time this run may hold before it is stopped, counted across every device it uses. A run nobody is watching cannot be told to stop, and a phone waits on a selector that will never match for as long as it is allowed to.

Build it
  1. Pick the method you will send

    A request using the other method still reaches the endpoint — it simply does not start a run. That keeps a health check from burning device minutes.

    WebhookSettings
    MethodGET or POST
    POST
  2. Send the shared secret with the request

    Either header works. There is no signature here because the sender is unknown — a shared secret is what a generic caller can manage.

    the request you send
    • POST…/api/hooks/<token>
    • X-Remonode-Secret••••••••••
    • or AuthorizationBearer ••••••
  3. What the endpoint does with it

    somewhere else
    your script · POST
    /api/hooks/…
    • the shared secret matches
    • the method matches the field above
    • a graph that waits for a person is refused — nobody answers at 4am
    • at most one run per endpoint every 30 seconds
    queued — 2 devices
What comes out
  • A queued run per accepted request, on the devices this trigger names.
Watch out
  • An unknown token and a disabled one both answer 404, identically. Telling them apart would turn the endpoint into a way to find valid tokens.
  • Anyone holding the URL and the secret can spend your device minutes. Rotate replaces both.
  • Running without a person needs the Starter plan — that covers a schedule and the endpoint an event trigger listens on. Run once still works on Free.
Usually next to