Docs / Platform
Automation tools
Connect Gurdx to Zapier, Make, n8n, IFTTT or any no-code tool by pointing a Gurdx webhook at the tool's "catch webhook" trigger.
The pattern#
- In the automation tool, create a scenario whose trigger is an incoming webhook, and copy its URL.
- In Gurdx (
https://gurdx.cretip.com/app, Settings, Webhooks), add a webhook with that URL and choose the event types. Save the secret. - Add the actions you want: create a ticket, append a spreadsheet row, message a person, call your own API.
- Trigger a live event and confirm the scenario receives a body like the one in Webhooks.
The payload always contains event, risk_score, user_identifier and occurred_at, plus fields specific to the event.
Zapier#
Use Webhooks by Zapier with the Catch Hook trigger. Zapier cannot verify HMAC signatures on its own, so add a Code by Zapier step first if you need verification, or put an unguessable token in the webhook URL path and keep the URL private. Then filter on risk_score with a Filter step before the action.
Make#
Add a Custom webhook module as the trigger. To verify the signature:
- In the webhook settings, enable Get request headers and Get request HTTP method, and set the data structure so the raw body is available as a text value.
- Add a Set variable module that computes an HMAC with SHA-256 over the raw body text, using your webhook secret as the key, and outputs it in hex. Prefix the result with
sha256=. - Add a filter on the next module that continues only when this value equals the
X-Gurdx-Signatureheader.
Function names differ between Make versions, so check the HMAC function in your scenario's formula picker.
n8n#
Use the Webhook node (method POST) with Raw Body enabled, then verify in a Code node:
const crypto = require('crypto');
const secret = $env.GURDX_WEBHOOK_SECRET;
// With Raw Body on, the exact bytes arrive as binary data named "data".
const raw = await this.helpers.getBinaryDataBuffer(0, 'data');
const expected = 'sha256=' + crypto.createHmac('sha256', secret).update(raw).digest('hex');
const received = $input.first().json.headers['x-gurdx-signature'] || '';
const a = Buffer.from(expected);
const b = Buffer.from(received);
if (a.length !== b.length || !crypto.timingSafeEqual(a, b)) {
throw new Error('Invalid Gurdx signature');
}
return $input.all();
Warning: Re-serialising parsed JSON can change whitespace and break the signature. Always enable Raw Body in the Webhook node so you hash the exact bytes Gurdx sent.
IFTTT#
Use the Webhooks service (Receive a web request) as the trigger. IFTTT cannot check signatures, so keep the URL secret and rely on filter code or a short forwarding service of your own for verification.
Good practices#
- Respond quickly. Most tools answer
2xxautomatically. If a step is slow, make it asynchronous so Gurdx does not hit its 10 second timeout. - Deduplicate on the
X-Gurdx-Deliveryheader, since retries can resend the same event. - Filter by
risk_scorein the tool rather than creating dozens of webhooks. - Do not auto-ban users from an unverified request. Verify first, and prefer routing to a human review queue.
Back to Integrations overview.
Found a mistake? Tell us on the contact page. Contact