Start with a test receiver
- Open a temporary webhook inspector and copy its unique HTTPS endpoint.
- In your YetiForm form's Actions, choose Webhook and connect that endpoint.
- Select Send test. Inspect the request method, headers, and JSON body in the inspector.
- Submit the real form once and compare the resulting request with the test event.
Move to your real endpoint
Your endpoint should return a 2xx status after it accepts a request. A non-2xx response is treated as a failed delivery and may be retried. Design the receiver so processing the same event more than once does not create duplicate records or actions.
What the signing secret does
YetiForm gives you a signing secret when you connect a webhook. It is for your own receiver to verify requests. The YetiForm-Signature header is an HMAC-SHA256 signature of the timestamp and raw body, and YetiForm-Timestamp carries that timestamp. A temporary inspector can display the request without checking its signature, but production receivers should verify it before trusting the payload.
Keep a record of what happened
The YetiForm submissions dashboard stores the response and shows delivery actions, so a failed downstream automation does not have to mean a lost form entry. Start with one destination, test failure handling, then expand to your CRM or internal workflow.