Webhooks allow Mudstack to send real-time updates from your workspace to external services. When an event happens (like a file upload, comment, or review), Mudstack will deliver a JSON payload to your configured endpoint.Only workspace admins can create, manage, or view webhooks.
Provide a URL for the endpoint that will receive the payloads.
Check Allow sensitive data to control if the payload will contain IP or just IDs. If this is unchecked, you must call the api upon receiving the payload.
Set which events should be sent to the webhook URL
Add custom headers if needed
The URL and Allow sensitive data options are not editable after creation
Webhooks cannot be edited. To change a webhook, you’ll need to delete it and create a new one. A Secret will be generated after creation for verifying webhook signatures.
{ "accountId": "b8f71389-2a45-4938-b6d5-0a70f9b9858c", "workspaceId": "2c8a5e43-58cb-47ec-b8a5-f0de2dcf9121", "type": "asset_review_added", "payload": { "assetId": "9d0ee2e7-3f25-4e38-b1cc-2cfb88f57df1", "createdAt": "2025-10-02T21:25:01.770Z", "authorName": "Joe Bell", "authorEmail": "josef@mudstack.com", "reviewId": "8f0c9b6e-24f5-4b9e-b5ac-6e593d6cd5ea", "reviewText": "<p>The color space on this export didn’t convert properly.</p>", "reviewType": "change_request" }, "id": "6a4f9cb0-2a2b-4b38-b621-d3db4cf94936"}
Reviews will have a reviewType of approved or change_request depending on the message.If Allow sensitive data is unchecked, the responses will only include the type, date, and ids.
Use our downloadable sample to automatically create Jira issues when new assets or tasks are added in Mudstack. You can import this into an Automation Rule and enter your webhook URL infoThe sample will parse a ticket id found at in the commitTitle on the commit_added event. This allows us to map the message to a specific ticket in Jira
Use Paths for splitting multiple event types in a single Zap
Use Formatter to convert Date / Time into something more human readable before sending to other systems.
You can use the Code block to concatenate assetIDs to generate links, make sure you pass in the input data from the webhook. These urls are only accessbile by users that have permssions in the account and workspace of the file.
# Extract the input valuesaccount_id = input_data.get('accountId', '')workspace_id = input_data.get('workspaceId', '')asset_id = input_data.get('assetId', '')# Construct the URL using string formattingurl = f"https://app.dev.mudstack.com/sh/asset/{account_id}/{workspace_id}/{asset_id}"# Prepare the output as a dictionaryoutput = {'url': url}
Webhooks push essential event data, but often you’ll need more context.You can use the Mudstack API in conjunction with webhooks to:
Fetch full asset metadata from an asset_id.
Retrieve commit details with a commit_id.
Join user and workspace information to enrich webhook payloads, like the user name or other file metadata.
Make sure to add this to your Automation
Make sure you have a step to authenticate before using the API.
GET Requests to gather additional information
The webhook response will contain the account, workspace, and object IDs for you to collect additional data from the APIIf you don’t currently have your API Key, ask us about generating your API KeyExample:
When a webhook sends asset_created with only an asset ID, call the API to fetch additional fields like tags, linked versions, or folder structure.
When attempting to GET Attachments from a comment or review, make sure to have an error handler. This will allow you to support posting when it returns with an error if there are no attachments on the comment.
Make sure file attachments are uploaded to their destination, NOT referencing the url. Our file urls have a 15 min time limit, so they must be uploaded and stored elsewhere to have any permanence.
Was this page helpful?
Assistant
Responses are generated using AI and may contain mistakes.