<!--
Sitemap:
- [Installation](/installation)
- [Upgrading](/upgrading): Version-specific steps for upgrading an existing Bento install.
- [Concepts](/concepts)
- [Build your first pipeline](/tutorials/pipeline-args)
- [Target a specific issue or PR from a URL](/tutorials/url-targeting)
- [Keep state across runs](/tutorials/pipeline-state)
- [Fire a pipeline on a schedule or on demand](/tutorials/schedule-and-fire)
- [Deploy a box to Railway](/tutorials/deploy-to-railway)
- [Operate a hosted daemon](/tutorials/operate-a-hosted-daemon)
- [Configuration](/configuration)
- [Members](/members)
- [Knowledge base](/knowledge-base/)
- [Method and delivery](/knowledge-base/modes)
- [Config](/knowledge-base/config)
- [MCP](/knowledge-base/mcp)
- [Pipeline configuration reference](/pipelines/config)
- [Filters](/pipelines/filters)
- [Triggers](/triggers/)
- [GitHub trigger](/triggers/github)
- [Linear trigger](/triggers/linear)
- [Webhook trigger](/triggers/webhook)
- [Schedule trigger](/triggers/schedule)
- [Manual trigger](/triggers/manual)
- [Traces](/pipelines/traces)
- [Slack](/integrations/slack)
- [Public access](/public-access)
- [Context engineering](/context-engineering)
- [Best practices](/best-practices)
- [Troubleshooting](/troubleshooting)
- [Architecture](/architecture/vision)
- [Workspaces](/workspaces)
- [Authentication](/authentication)
- [Identity](/identity)
- [Security](/security)
- [References](/references)
- [Changelog](/changelog): Bento release history.
- [CLI reference](/cli/)
- [Setup](/cli/setup)
- [Secrets](/cli/secrets)
- [Lifecycle](/cli/lifecycle)
- [Sandbox image](/cli/image)
- [Sandboxes](/cli/sandbox)
- [Observability](/cli/observability)
- [Diagnostics](/cli/diagnostics)
- [Triggers](/cli/triggers)
- [Workbench](/cli/workbench)
- [Auth](/cli/auth)
- [Knowledge](/cli/knowledge)
- [Evals](/cli/evals)
- [Bento](/index)
- [Runtime wrapper](/architecture/runtime-wrapper)
- [Skill evolve](/architecture/skill-evolve)
-->

# Webhook trigger

Any HTTP POST to `/webhooks/{name}` fires a webhook trigger. The trigger name matches the `{name}` path segment.

```yaml
# Fires on POST /webhooks/deployment
trigger:
  webhook:
    - deployment
```

## Authentication

Declare a source for each webhook name in `daemon.yaml`. The key names the route. Set `verify: bearer` for this trigger. A `github` or `linear` source delivers provider events through `trigger.github` or `trigger.linear` instead:

```yaml
webhooks:
  sources:
    deployment:
      verify: bearer
      secret: ${BENTO_DEPLOYMENT_WEBHOOK_TOKEN}
```

To store the token in Postgres, run `bento setup webhook deployment --secret-env BENTO_DEPLOYMENT_WEBHOOK_TOKEN`. Create or restore the [instance key file](/cli/secrets) before setup. Replace `secret` with a reference:

```yaml
webhooks:
  sources:
    deployment:
      verify: bearer
      secret_ref: webhook/deployment
```

Use exactly one of `secret` and `secret_ref`. A reference is the full secret name, `webhook/<name>`. Restart the daemon after setup. Missing or unreadable database credentials prevent startup. See [key rotation](/cli/secrets#rotate) for the rotation procedure.

The caller sends it as a bearer token:

```bash
curl -X POST https://your-daemon/webhooks/deployment \
  -H "authorization: Bearer $BENTO_DEPLOYMENT_WEBHOOK_TOKEN" \
  -H "content-type: application/json" \
  -d '{"status":"success"}'
```

The daemon compares the token in constant time and answers `401` if it does not match. It records no event for a rejected request.

A route with no source rejects every request, exactly as it rejects a wrong token, so a caller learns nothing about which names exist. The daemon refuses to start if a pipeline declares a webhook trigger whose source is missing while the daemon is reachable off the machine. See [Security](/security#webhook-validation).

## Example

```yaml
trigger:
  webhook:
    - deploy-complete
agent: notifier
instructions: |
  A deployment just completed. Summarize the event and report the outcome.
```

## See also

* [Filters](/pipelines/filters) — narrow which events reach this pipeline
* [Public access](/public-access) — expose the daemon to receive webhooks
