Add Webhook
Creates a webhook that receives real-time POST callbacks for selected events.
Available event types
When creating a webhook, you can subscribe to specific events using thetype field. Events are organized by category below.
Lead state groups
These aggregate multiple activity types into a single lead-state change event.Email activities
LinkedIn activities
WhatsApp activities
SMS activities
Call activities
API activities
Manual activities
Task activities
Workspace activities
Enrichment
Inbox activities
Signal Agents
Deliverability hub
Deprecated events
These events have been removed from the API. Use the replacements below.Verifying webhook authenticity
You can pass an optionalsecret in the request body when creating the webhook. It works like a shared password between lemlist and your endpoint:
- Stored encrypted at rest.
- Never returned by
GET /hooksor any other endpoint. - Immutable — it cannot be changed after creation. To rotate it, delete the webhook and create a new one.
- Sent back to your endpoint as a
secretfield in the JSON body of every webhook call, so you can verify the request originated from lemlist.
Webhook payload
Each event is delivered as aPOST to your targetUrl with a JSON body that mirrors the underlying activity record. Common fields:
Email recipients (to / cc / bcc)
Email events (emailsSent, emailsReplied, emailsBounced) carry the full recipient lists as arrays of {address, name}. Addresses are lowercased. Fields are omitted when empty.
to— primary recipient(s). For outbound sends, this is the lead. For inbound replies, this is the mailbox owner; multi-recipienttolines (e.g. reply-all where the lead manually added people) are preserved.cc— explicit CC recipients on the email.bcc— only present for outboundemailsSentevents when the sender has a hidden BCC configured in Settings → Integrations (users.lemlist.bcc). Inbound BCC is never visible because SMTP strips it for non-BCC’d recipients.
Third-party reply flag
When a reply on a thread comes from an address that does not match the original lead’s known contact emails, lemlist attributes the reply to the third-party sender rather than to the lead, and the event carries an extra flag:campaignId, leadId, and sequenceId (since the reply is no longer attached to the original campaign flow). Use the flag to route these events differently if needed.
Examples
zapId if you use Zapier to track the webhook mapping on your side.Authorizations
Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.
Query Parameters
Webhook for specific campaign
Webhook for first activity only
Zapier ID
Body
The URL that will receive webhook POST requests.
Optional event type to subscribe to. When omitted, all events are sent. See the full categorized list in the endpoint documentation.
contacted, hooked, attracted, warmed, interested, notInterested, emailsSent, emailsOpened, emailsClicked, emailsReplied, emailsBounced, emailsFailed, emailsInterested, emailsNotInterested, emailsUnsubscribed, linkedinSent, linkedinOpened, linkedinReplied, linkedinInterested, linkedinNotInterested, linkedinSendFailed, linkedinVisitDone, linkedinVisitFailed, linkedinFollowDone, linkedinFollowFailed, linkedinFollowSkipped, linkedinInviteDone, linkedinInviteFailed, linkedinInviteAccepted, linkedinEndorseDone, linkedinEndorseFailed, linkedinEndorseSkipped, linkedinVoiceNoteDone, linkedinVoiceNoteFailed, linkedinLikeLastPostDone, linkedinLikeLastPostNoPost, linkedinLikeLastPostFailed, linkedinWithdrawInvitationDone, linkedinWithdrawInvitationFailed, whatsappMessageSent, whatsappMessageDelivered, whatsappMessageOpened, whatsappReplied, whatsappMessageFailed, smsSent, smsDelivered, smsReplied, smsFailed, aircallCreated, aircallEnded, aircallDone, aircallInterested, aircallNotInterested, apiDone, apiInterested, apiNotInterested, apiFailed, manualInterested, manualNotInterested, paused, resumed, stopped, campaignComplete, customDomainErrors, connectionIssue, sendLimitReached, lemwarmPaused, annotated, enrichmentDone, enrichmentError, callRecordingDone, callTranscriptDone, inboxLabelUpdated, signalRegistered, deliverabilityAlertTriggered Optional shared secret. Stored encrypted, never returned by GET, and immutable once set. Sent back to your endpoint as a secret field in the body of every webhook call so you can verify the request originated from lemlist.