Pulse Webhooks push platform events straight to your firm's own systems — your CRM, a Slack channel, a reporting pipeline — the moment they happen. As a firm admin you create an endpoint (a URL plus a signing secret), pick the events you care about, and Pulse delivers each one as a signed JSON POST. Your endpoint only ever receives events for **your firm's own clients** — never another firm's data.

**💡 Tip — Who can use this**\
Firm administrators, from **Settings → Webhooks** in the firm portal. Any HTTPS URL your system controls works. Delivery retries automatically if your endpoint is briefly down.

## Quick reference

| Step | Action                                     |
| ---- | ------------------------------------------ |
| 1    | Open Settings and find the Webhooks card   |
| 2    | Create an endpoint with its URL and events |
| 3    | Copy the signing secret                    |
| 4    | Confirm delivery with a test event         |

---

## Step 1: Open Settings and find the Webhooks card

In the firm portal, click **Settings** and scroll to the **Webhook Endpoints** card. The card lists your firm's endpoints, what each is subscribed to, its status, and recent deliveries.

\
![](https://desk.lucidusfortis.com/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBYUT09IiwiZXhwIjpudWxsLCJwdXIiOiJibG9iX2lkIn19--ad7b2ee03a9b414d7f940faa5fdc3cf1e4da486b/image.png)

## Step 2: Create an endpoint with its URL and events

Click **Create Endpoint**. Give it the HTTPS URL of the system that will receive events and a short description. Then choose its **event subscriptions** — grouped by area so you can scan quickly:

* **Lifecycle** — signups, leads, onboarding milestones

* **Billing** — subscriptions started/renewed, tier changes, account state, grace, deactivation, firm suspension

* **Engagement** — data submissions, scores, advisory published, decisions, sessions, documents

* **Messaging** — messages sent or promoted (**high volume** — subscribe only if you truly need it)

* **Platform** — partners and team changes, clients created, pricing updates

Remember the scoping rule: even if you subscribe to an event type, your endpoint only receives the instances where the client organization has an active engagement with **your firm**.

![Create endpoint dialog with event catalog](https://brandassets.lucidusfortis.com/help/firm-webhooks/step-2-create-dialog.png)

**📝 Note — You can change subscriptions anytime**\
Open the endpoint's **Edit** dialog and re-check the list — subscriptions update immediately, no downtime.

## Step 3: Copy the signing secret

When the endpoint is created, Pulse shows its **signing secret** (`whsec_…`). Your receiving system uses this secret to verify that deliveries genuinely come from Pulse. You can view the secret again at any time with **Reveal Secret**, and replace it with **Rotate Secret** if it ever leaks — after rotating, update your receiving system promptly.

![Signing secret modal](https://brandassets.lucidusfortis.com/help/firm-webhooks/step-3-signing-secret.png)

**❗ Important — Verify every delivery**\
Each POST carries an `X-Pulse-Signature` header (an HMAC of the timestamp + raw body, made with your secret). Verify it on your side before trusting the payload — the exact recipe is in the platform's webhook documentation, and the help center's admin article includes a working code snippet.

## Step 4: Confirm delivery with a test event

Click **Send Test** on your endpoint's row. Pulse queues a synthetic test event immediately — no need to wait for a real signup or renewal. The card's **Recent Deliveries** table then shows the outcome per delivery: succeeded, pending a retry, or dead-lettered after repeated failures. In the screenshot below the demo endpoint's URL doesn't actually exist, so its delivery keeps retrying with a growing delay — a real endpoint that answers shows **Succeeded**.

![Endpoint listed with delivery log](https://brandassets.lucidusfortis.com/help/firm-webhooks/step-4-endpoint-and-log.png)

**📝 Note — How retries work**\
If your endpoint is unreachable or returns an error, Pulse retries with growing delays (from about a minute up to a day). Deliveries are **at-least-once** — if your system processes an event twice, use the delivery id from the `X-Pulse-Delivery` header to deduplicate. An endpoint that keeps failing for many deliveries is automatically disabled and your firm admins are notified; you can re-enable it from the same card for a fresh start.