RMM Labs
Integrations 4 min read 28 September 2026 By Fred

How to set up outgoing webhooks in Xcellerate OPS

Send Xcellerate OPS events as JSON to your own URL, with optional HMAC signing. Here is how to set up outgoing webhooks and what to watch out for.

How to set up outgoing webhooks in Xcellerate OPS

Xcellerate OPS emits an event every time something happens: a ticket is created, a quote is accepted, an invoice is created, a call is missed. With outgoing webhooks you send those events as JSON to your own URL, so Zapier, Make, n8n, Power Automate or your own system can act on them straight away. This guide is for admins at MSPs and service businesses who want OPS to drive their other tools.

TL;DR

  • Go to Settings → Data and security → Notifications and webhooks and add one URL per event.
  • OPS sends one JSON POST per event, immediately, optionally signed with HMAC-SHA256.
  • Each delivery is sent once, without retries: pick a receiver that is always available and answers fast.

Before you start

  • You have the admin role in your OPS workspace.
  • You have an endpoint that accepts POST requests with Content-Type: application/json and responds within 8 seconds.
  • The URL resolves to a public address. Private or internal addresses are refused. Prefer HTTPS.
  • Optional: a shared secret so your receiver can verify the signature.

Set up an outgoing webhook

Step 1: Open the events page

Go to Settings → Data and security → Notifications and webhooks. Events are grouped by area. Event names are shown in English with their technical key, for example "Ticket created" (ticket.created).

Notifications and webhooks settings page in Xcellerate OPS The Notifications and webhooks page, with options per event for notifying the assignee, customer email, email template and a button to add a webhook.

Step 2: Add a webhook to an event

Find the event you want to forward and click Add webhook. Enter the URL of your receiver.

Step 3: Set a signing secret (optional)

Fill in Signing secret (optional). Every request then carries the header X-Signature: sha256=<hex>: an HMAC-SHA256 of the raw JSON body, keyed with your secret. Your receiver computes the same value and compares. The secret is not shown again after saving. If you leave the field blank when you save, the stored secret is kept.

Step 4: Send a test

Click Test to send a sample payload for that event. The test only confirms that OPS could send the request. It does not tell you what your endpoint did with it. So always check on the receiving side, in your tool's history or logs, that the sample arrived and was processed correctly.

Step 5: Save and repeat

Click Save at the top of the page. Repeat for every event you want to forward: you set one URL per event type.

What happens after you connect

  • Direction: from OPS to your URL. One POST per event, sent the moment it happens.
  • Content: every message has the same envelope. The data field differs per event.
{
  "event": "ticket.created",
  "label": "Ticket created",
  "occurredAt": "<ISO-8601>",
  "title": "…",
  "link": "/tickets/…",
  "data": { … }
}
  • Coverage: over 160 event types, including tickets, clients and contacts, CRM tasks, projects, budgets, timesheets, invoices, contracts, quotes, assets, calls, opportunities, working time, ITIL changes, problems and incidents, and AI colleagues.
  • Notifications: the same page also controls in-app notifications per event, Notify assignee and customer email templates for ticket events.

To see what else you can automate, have a look at automation in OPS and EU integrations and security.

Good to know

  • Sent once, no retries. There is no retry and no delivery log. If your receiver is down or too slow, that event does not arrive. Use a reliable receiver: an automation platform, or your own endpoint that stores the message, answers at once and processes it afterwards.
  • 8-second timeout, and redirects are not followed. Use the final URL.
  • One URL per event type. To feed several systems with the same event, let your receiver fan it out.
  • Bulk imports and merges never fire webhooks.
  • The URL is checked again for a public address at the moment of sending.

Troubleshooting

  • "Sample payload sent." The test request went out. Check on your receiver that it was also processed.
  • "Webhook test failed: " A connection-level failure, such as DNS, a timeout or TLS.
  • Validation error on save. The URL is invalid or resolves to a private or internal address.
  • Real events do not arrive, although the test worked. Check that your endpoint responds quickly, without redirects, and is still reachable on a public address.

Get started

Want OPS to pass your tickets, quotes and invoices to the rest of your tools? Get started for free and set up your first webhook from Settings.

Frequently asked questions

Does OPS retry a failed webhook?
No. Each event is sent once, without retries and without a delivery log. Use a receiver that is always available and responds within 8 seconds.
How do I verify that a webhook really comes from OPS?
Set a signing secret. Every request then includes the X-Signature header with an HMAC-SHA256 of the raw body, which your receiver can recompute.
Can I send one event to several URLs?
No, you set one URL per event type. To serve several systems, let your receiver forward the message.
Sources: Verified against the Xcellerate OPS source code by the product team on 2026-09-28. Feature pages: https://rmmlabs.io/en/products/ops/features/automation; https://rmmlabs.io/en/products/ops/features/integrations-eu. Screenshots: real captures of the Xcellerate OPS demo workspace, Sep 2026.

Ready to solve time registration compliance?

Xcellerate OPS covers Belgian 2027 time registration requirements out of the box — no extra module needed.

Related articles