What we do
Tools
Industries
Department
How we workLet's talk →
Home/Zapier/Zapier Webhooks
Zapier

Webhooks by Zapier: The Generic Connector for Everything Else

Webhooks by Zapier is a built-in app inside the Zap builder, not a separate product: Catch Hook and Catch Raw Hook start a Zap when an outside system sends data to a Zapier-generated URL, and Custom Request sends an outbound HTTP call to any endpoint you point it at. It's how a Zap reaches a system with no native Zapier integration at all. It wasn't built to be the reliable, secure connection a business-critical workflow actually needs, and that gap is where our work usually starts.

What the built-in webhook steps actually do

Catch Hook gives you a unique URL the moment you add the trigger, and any system that can send an HTTP request to that URL starts a Zap, no native integration required on either end. Catch Raw Hook works the same way but hands you the entire request body untouched, useful when the sender's payload doesn't match what Catch Hook expects to parse automatically. Retrieve Poll checks an endpoint on a schedule instead of waiting for an inbound call, which matters for a system that can't send webhooks out on its own.

On the outbound side, Custom Request builds an HTTP call from inside a Zap: pick a method, set headers, write a JSON or form body, and send it to any URL, including systems with zero presence in Zapier's app directory. For a one-off connection to something genuinely obscure, this is often the only practical option short of custom code.

Where the generic connector stops being enough

Authentication is the first wall most people hit. Custom Request handles Basic auth cleanly and an API key in a header without much trouble, but a system that needs OAuth2 token refresh, a signed request (HMAC, AWS SigV4), or a rotating token has no built-in support, the Zap either breaks silently when a token expires or someone has to refresh it by hand.

Reliability is the second wall. A failed Custom Request call shows up in Zapier's task history, but there's no automatic retry with backoff, no dead-letter queue, and no alert unless you build one yourself with another Zap watching for failures. For an inbound Catch Hook, Zapier doesn't verify the sender signed the payload unless the sending system supports it and you build that check in yourself; anything that can guess the URL can fire your Zap.

Volume is the third. Each webhook call is a task the same way any other Zap step is, so a high-frequency integration running through Custom Request racks up cost the same way it would through a native connector, without getting any more resilient for the money.

What we build once a webhook connection matters

01

A webhook endpoint with real retry logic

Instead of a Custom Request step that fails quietly when a token expires, we build the connection with token refresh, retries with backoff, and a log you can actually check when something doesn't go through.

02

Signed, verified webhooks both ways

Inbound payloads get their signature checked before anything acts on them, and outbound calls to a system that requires signed requests get built to actually produce one, not approximated with a static header.

03

What's running through a Custom Request step right now that would hurt if it failed silently?

If a webhook connection handles money, orders, or anything else that matters when it breaks, tell us what it's doing and we'll scope a version built to not fail quietly.

Let's talk

Got a Catch Hook or Custom Request step holding together a connection that actually matters?

Tell us what's on the other end of it and what happens the day it silently stops working. We'll give you a straight read on whether that's still fine as a Zapier webhook or needs a sturdier connection built directly. Webhooks are one example; n-frames builds this same reliability layer for whatever else in your business is running on hope.

Let's talk →

Questions people ask

What is Webhooks by Zapier?

A built-in app inside the Zap builder, not a separate product, that lets a Zap start when an outside system sends it an HTTP request (Catch Hook, Catch Raw Hook) or send its own outbound HTTP request to any URL (Custom Request), useful for connecting to systems with no native Zapier integration.

How do I catch a webhook in Zapier?

Add a Catch Hook trigger to a new Zap and Zapier generates a unique URL immediately. Point whatever system you're connecting at that URL, send it a test request, and Zapier uses that sample to map the incoming fields for the rest of the Zap.

What's the difference between a Zapier webhook and the Zapier API?

Webhooks by Zapier is a step inside a Zap you build for yourself, catching or sending HTTP requests as part of your own workflow. Zapier's developer platform and API are a different thing entirely: the tools a software company uses to publish its own app into Zapier's directory for other customers to use, not something you'd reach for to connect your own systems.

Does Zapier verify that a webhook actually came from who it claims?

Not on its own. A Catch Hook URL will accept a request from anywhere unless the sending system includes a signature and you build a step to check it. Treat an unverified webhook URL as something worth keeping private, not as a secured endpoint by default.

Can Custom Request handle OAuth2 authentication?

It can send a token in a header once you have one, but it doesn't manage the refresh cycle for you. A token that expires mid-workflow needs either a separate Zap to refresh it or a custom-built connection that handles that automatically.

Why did my Zapier webhook stop working with no error shown?

Usually an expired token, a changed payload shape on the sending end, or a failed Custom Request call that logged in Zapier's task history without triggering any alert, since Webhooks by Zapier doesn't notify you on failure unless you've built a separate Zap to watch for it.

Let's talk

Tell us the one thing your team does manually that eats up time. We read every message and reply within a day.