Webhooks + CaptiFi
Get guest sign-ups pushed to your own systems the second they happen, with signed payloads, automatic retries and a delivery log. Included on Growth and above.
What does the Webhooks integration do?
Webhooks push events to your own systems the moment they happen: a guest signs up on your WiFi for the first time, or a returning guest connects again, and your booking system, CRM or automation tool knows a second later. Add up to five HTTPS endpoints; each request is signed with HMAC SHA-256, failed deliveries retry with backoff and every attempt is logged for 30 days. For teams with their own stack. Included on the Growth plan and above.
Webhooks turn CaptiFi into an event source for the rest of your stack. Instead of asking the API what changed, you give CaptiFi an HTTPS URL and CaptiFi posts to it the moment something happens: a guest signs up on your WiFi for the first time, or a guest who has been before connects again. Rewards, Events and bookings add their own: a reward issued or redeemed, points earned, a ticket order paid, checked in or refunded, a booking or ticket holder turning up. Your booking system, CRM or automation tool knows about it a second later.
Add up to five endpoints, which is handy for pointing the same events at a live system and a staging one, and tick the events each endpoint should receive. Every request carries an HMAC SHA-256 signature over the raw body, along with the event name and a delivery id, so you can prove a payload came from CaptiFi before you trust it and treat a repeat of the same id as one event.
Delivery is built for the real world. A failed attempt retries automatically with backoff, every attempt is recorded for 30 days with the response code and how long your server took, and an endpoint that keeps failing is switched off rather than hammered forever. You can fire a test event while you build, and rotate a signing secret whenever you need to. Webhook payloads contain guest personal data, so CaptiFi will only send them over HTTPS, and once a copy reaches your systems your own retention and deletion obligations apply to it.
Why connect Webhooks to CaptiFi
React the moment a guest arrives
A guest signs in and your system hears about it a second later, so welcome journeys, CRM records and ops alerts fire on arrival instead of on your next scheduled poll.
Signed payloads you can verify
Every request carries an HMAC SHA-256 signature over the raw body plus a timestamp, so you can reject anything that is not genuinely from CaptiFi and anything replayed later.
Retries and a delivery log
Failures retry automatically with backoff, and every attempt is logged for 30 days with the response code and duration, which answers "did CaptiFi send it, or did my server reject it?" in seconds.
Up to five endpoints, live and staging
Point the same events at production and a test environment, switch an endpoint off without deleting it, send a test event while you build, and rotate a signing secret when your security policy says so.
What data flows to Webhooks
Up and running in minutes
Add an endpoint
Open Webhooks in your CaptiFi dashboard, paste the HTTPS URL that should receive events, and tick the events you want. The URL must be HTTPS: payloads contain guest personal data and are never sent unencrypted.
Verify the signature
Compute an HMAC SHA-256 of the timestamp and the raw request body using your endpoint signing secret, compare it in constant time with the X-CaptiFi-Signature header, and reject anything older than five minutes. Always verify before you trust a payload.
Send a test event and go live
Fire a test event from the dashboard to confirm your handler accepts it, then switch the endpoint on. Answer with any 2xx as soon as you have accepted the event and do the slow work afterwards.
Watch the delivery log
Each attempt is listed with the event, attempt number, response code and duration, kept for 30 days. De-duplicate on the event id so a retry is never processed twice.
Step by step, with screenshots.
How venues use Webhooks with CaptiFi
A hotel pushes every new WiFi sign-up into its PMS-linked CRM on arrival, so the front desk sees a returning guest flagged before they reach the counter.
A guest.returned event triggers an internal alert for regulars, letting the floor team greet frequent diners by name without anyone watching a dashboard.
New sign-ups post straight into a low-code automation tool, which adds the contact to an email platform, tags the store branch and starts a first-visit voucher sequence.
Frequently asked questions
Which plans include webhooks?
Which events can I subscribe to?
How do I know a request really came from CaptiFi?
What happens if my server is down?
Could I receive the same event twice?
Who is responsible for the guest data once it reaches us?
Pairs well with
Start using Webhooks with CaptiFi today
30-day free trial. Cancel anytime.
Google, Gmail, Mailchimp, Klaviyo, HubSpot, Salesforce, Facebook, Meta Pixel, Slack, Zapier, Twilio, Tripadvisor, Yelp, Toast, Square, SumUp, Airship, Revinate, Leat, Pepper, EmailOctopus, Incentivio and ChatGPT are trade marks of their respective owners and appear here only to identify the services CaptiFi connects to. CaptiFi is independent of these companies and is not sponsored, certified or endorsed by them. An integration marked coming soon is on our roadmap and is not yet available. Twilio and all related logos are trademarks of Twilio Inc. or its affiliates. Salesforce is a trademark of Salesforce, Inc. Slack is a trademark and service mark of Slack Technologies, Inc., registered in the U.S. and in other countries.
CaptiFi is a guest WiFi marketing and captive portal platform for restaurants, bars, pubs, cafes, hotels, gyms, salons, retail and short-term rentals, built by CaptiFi Ltd in the UK and sold in GBP, USD, EUR, CAD, AUD and NZD to venues worldwide.