Skip to content
All guides

Get updates with webhooks

Have Shog tell your system the moment someone is added, finishes a course or earns a certificate.
Updated 2026-10-09

What it is for

A webhook is a message Shog sends to your server when something happens, so your system does not have to keep asking. It can say that:

  • an employee was added, changed or deactivated;
  • someone was enrolled, completed or failed a course, had an enrolment cancelled, or was given another attempt;
  • a certificate was issued.

The message names what happened and carries IDs, not personal details. Your system then reads the record it needs through the API.

Add a destination

  1. Open the company, then Integrations and Webhooks.
  2. Choose Add destination, give it a name and your server's HTTPS address. The address cannot be changed later; add a new destination if your server moves.
  3. Tick the events that server needs.
  4. Copy the signing secret when it is shown. It is shown once.
  5. Set up signature checking on your server, use Send sample, then Enable the destination.

Worth knowing

A new destination starts disabled, so nothing arrives before your server is ready to check it. A company can have up to three active destinations.

Check every message

Each message carries three headers: webhook-id, webhook-timestamp and webhook-signature. Your server should sign the raw body with the destination's secret and compare, refuse a message whose timestamp is more than five minutes old, and ignore an ID it has already handled. Events and signing shows a receiver you can copy.

When your server is down

Answer with any 2xx quickly, then do the work. A message that gets no answer, or anything other than a 2xx, is tried again with growing gaps for up to 72 hours. Deliveries shows the last 30 days, each attempt and its payload, and lets you send one again.

Read next