Integrations
Webhooks & Payloads
Receive real-time HTTP POST notifications whenever a respondent completes your form.
Webhooks & Payloads
Webhooks allow you to push submission data in real-time to your backend APIs, AWS Lambda, Cloudflare Workers, or automation platforms.
Webhook Payload Structure
When a form submission occurs, InfiForm dispatches an HTTP POST request with Content-Type: application/json:
{
"event": "form.submission.created",
"formId": "form_abc123",
"submissionId": "sub_987654321",
"submittedAt": "2026-10-03T10:30:00.000Z",
"answers": [
{
"fieldId": "fld_name",
"question": "What is your full name?",
"type": "short_text",
"value": "Jane Doe"
},
{
"fieldId": "fld_email",
"question": "What is your work email?",
"type": "email",
"value": "jane@example.com"
},
{
"fieldId": "fld_rating",
"question": "How satisfied are you with our service?",
"type": "rating",
"value": 5
}
],
"metadata": {
"ipAddress": "198.51.100.42",
"userAgent": "Mozilla/5.0 ...",
"referer": "https://example.com/pricing"
}
}HMAC Signature Verification
To ensure that the incoming webhook originated from InfiForm and was not tampered with, InfiForm signs every request using your webhook secret.
The signature is sent in the X-InfiForm-Signature HTTP header:
import crypto from "crypto";
export function verifyWebhook(rawPayload, signatureHeader, secret) {
const hmac = crypto.createHmac("sha256", secret);
const calculatedSignature = "sha256=" + hmac.update(rawPayload).digest("hex");
return crypto.timingSafeEqual(
Buffer.from(calculatedSignature),
Buffer.from(signatureHeader)
);
}Retries & Error Handling
- Successful Response: Your endpoint should return an HTTP
2xxstatus code within 10 seconds. - Automatic Retries: If your endpoint returns an error (
5xxor429) or times out, InfiForm will automatically retry with exponential backoff up to 5 times over a 24-hour period.