Where you set this up
Business defaults
Open Business → Integrations & events.- Webhook
- Email notify
- In-app notify
- Turn Enabled on.
- Enter the HTTPS URL Documate should POST to.
- Optionally set a shared secret (used to sign the POST).
- Tick the events you want on the webhook.
- Save.
Channel override
Open Channels & intake → Intake.- Leave Inherit Business defaults on to use the business webhook URL, secret, and event ticks.
- Uncheck inherit to set a different URL, secret, and event list for this channel only. Email and in-app still follow the business settings.
Live delivery uses the effective channel webhook config (inherited or overridden).
How events are sent
When a subscribed event happens, Documate does the following for each enabled destination that has that event ticked:
Nothing is sent if that destination is off, or if the event is not ticked.
Events are not sent when:
- You use sync extract (
api_sync). - You only poll the partner API. Polling does not create events.
- The file or document never reaches that state (for example a document that stays Processing).
Available events
The app shows Title Case labels. Webhooks use the dotted key.Test a webhook
On Business → Integrations & events, use Test next to the webhook URL. Documate posts a sample payload for a recent file or document.- Test POSTs include
X-Documate-Test: true. - Signing still uses your secret when one is configured. Verify
X-Documate-Signature; do not treat the test header as authentication. - Test prefers the business secret you just saved. Live traffic still uses the effective channel config.
Payload and verification
Webhooks never include raw file bytes. You get IDs and optional short-lived download URLs. See Webhooks for the JSON shape, headers, and how to download the original file afterfile.received. See API webhooks for signature samples.