Which webhook events are available and how are they signed?
Updated Oct 7, 2026
Events: link.created, link.clicked, link.deleted, overlay.response and bio.submission. Each delivery is signed with HMAC-SHA256 in the X-ShortGo-Signature header.
ShortGo can send these webhook events to your endpoint:
link.created,link.deletedlink.clicked— high volume, so make sure your endpoint can keep upoverlay.response— a visitor answered a CTA overlay (form, poll, signup…)bio.submission— a form on a bio page was submitted
Every delivery is signed with HMAC-SHA256. The signature is in the X-ShortGo-Signature header as sha256=..., computed over <timestamp>.<body> with your webhook secret. Recompute it on your side and reject mismatches. Failed deliveries are retried. Details are at /developers.
Was this article helpful?
Thanks for the feedback! Still stuck? Contact support