An answer comes in.
Your workflow begins.
Send completed form submissions straight to your apps, automations, or API. Set it up once. Keep your work moving.
Included on Free, Pro, and Business.
A new submission
Your respondent completes the form.
Their answers are ready to go.
The next step happens
Add a lead. Notify your team.
Start the process you designed.
THREE STEPS. ONE CONNECTION.
Put your answers to work.
- 1
Get your endpoint
Create an HTTPS webhook endpoint in your automation tool or your own application.
- 2
Connect your form
Open Integrations in your form, paste the endpoint URL, and save with delivery enabled.
- 3
Send a test
Check the sample event reaches your endpoint. New completed submissions will follow automatically.
A connection you can keep an eye on.
Signed events
Verify that an event came from trulyform using your private signing secret.
Automatic retries
Temporary connection failures, rate limits, and server errors get another chance.
Delivery history
See delivery status and HTTP results, then retry failed events when you are ready.
A little more detail.
Can I connect Make, Zapier, or my own app?
Yes. Use the incoming webhook URL from your workflow, or an endpoint you build yourself. Automation services manage their own accounts and pricing. Your endpoint must use public HTTPS on port 443, accept JSON POST requests, and return a 2xx status within 10 seconds. Redirects are not followed.
What does a submission event contain?
Events include a stable event ID, schema version, form and published-version identifiers, completion time, answers with stable field IDs and readable labels, hidden fields, and calculations. Number-question values are decimal strings to preserve precision. File answers include identifiers and file metadata; file contents and download credentials are not sent.
{
"id": "your-event-id",
"type": "response.completed",
"schema_version": 1,
"created_at": "2026-10-01T12:00:00Z",
"data": {
"form": { "id": "form-id", "name": "Contact us", "version_id": "version-id", "version": 1 },
"response": {
"id": "response-id",
"completed_at": "2026-10-01T12:00:00Z",
"answers": [{ "field_id": "field-id", "kind": "email", "question": "Your email", "value": "[email protected]", "display_value": "[email protected]" }],
"metadata": {}, "calculations": {}, "files": []
}
}
}How do I verify a signature?
Read the Webhook-Timestamp and Webhook-Signature headers. Compute an HMAC-SHA256 over the timestamp, a period, and the exact raw request body using your signing secret. Compare against the signature after its v1= prefix using a constant-time comparison. Reject timestamps more than five minutes from your current time and deduplicate processed Webhook-Id values. The Idempotency-Key header contains that same event ID.
$expected = hash_hmac("sha256", $timestamp . "." . $rawBody, $signingSecret);
$valid = hash_equals("v1=" . $expected, $signature);What happens if delivery fails?
Transient failures receive up to five attempts, with increasing delays of approximately one minute, five minutes, thirty minutes, and two hours. Other 4xx responses and redirects fail without automatic retries. You can manually retry a failed delivery. Retries use the original payload and event ID, so your receiver should process each event once even if it arrives more than once. Changing the endpoint, disabling the integration, or rotating the secret cancels outstanding deliveries for the old configuration; an in-flight request may finish.
Do webhooks send unfinished responses?
This integration sends new completed submissions after you enable it. Test events contain sample data and do not count as form responses.