Webhook Actions – build automations and integrations with AI help

Opis

Describe the integration you want. The AI builds it. Webhook Actions ships with Build with AI — an in-admin agent that turns a plain-language request like „When a Contact Form 7 form is submitted, send it as JSON to my n8n webhook” into a working, tested automation. The agent proposes a plan you can review and edit, then creates the webhook, works from a real example payload — your site’s own capture, or the Payload Library for an event your site has never fired — maps the fields, sets dispatch conditions, probes your endpoint, and sends a test delivery. Nothing goes live without your confirmation — new webhooks are always created disabled, and you can undo the last change with one click.

It reads the API before it builds. Name HubSpot, OpenAI, Slack, Stripe, Notion or any of the 300+ services in the WP Webhooks API Docs Library and the agent works from that vendor’s current API reference — endpoint, auth header, body envelope, the errors people actually hit — not from the model’s memory of it. A service the library has never seen is researched from the vendor’s own docs on the spot, and every reply built this way says so.

📖 Full documentation at wpwebhooks.org/docs/
▶️ Try it in your browser — no install, no signup, no API key

What you can connect

Sources — anything in WordPress that fires an action. Webhook Actions turns any do_action into a trigger, so form submissions, WooCommerce orders, user registrations, post publishes and your own custom plugin events can all start an automation. That covers Elementor Forms, WPForms, Forminator, Fluent Forms, Gravity Forms, WooCommerce and your own code — there is no per-plugin add-on to hunt down. Contact Form 7 and IvyForms go one step further with built-in support: their submissions are normalized into clean JSON payloads automatically.

Destinations — any HTTP endpoint. The plugin sends outgoing webhooks to anything that accepts a request: an n8n, Make (formerly Integromat), Zapier or Pabbly webhook node, a Slack or Discord incoming-webhook URL for order and form notifications, Airtable, Google Sheets, Mailchimp, HubSpot, Salesforce, Notion, your CRM, an internal microservice, or an AI agent API. There are no bundled per-service connectors and none are needed — point a webhook at a URL, map the fields, and send. Every delivery is queued, retried on failure and logged with full request and response history.

That makes it a no-code way to sync WordPress data outward: describe what you want in chat and let the AI build it, or wire it up by hand in the admin UI. No PHP required either way.

No API key needed to start

  • 55 free credits, no key and no signup — claimed automatically on your first prompt. There is no button to press, no account to create and no card; the plugin sends nothing but your site address. That is about five agent turns, or roughly two complete automations built end to end
  • Try it without installing anythingLive Preview (also the button at the top of this page) boots a throwaway WordPress in your browser and runs the real agent on those credits
  • WordPress connectors — if your site already has an AI provider connected (Settings Connectors), the builder uses it directly and the plugin stores no keys
  • My own keys — connect Anthropic, OpenAI or Google in the builder; keys are encrypted in the Credentials Vault and never returned over the API. A free Google AI Studio key gives you Gemini at no cost: step-by-step tutorial
  • Your own key always wins — once a provider of yours is connected, the free credits are never spent
  • Automatic fallback — if a provider is rate-limited mid-build, the agent switches to another connected provider and keeps going

What the AI works from

The agent doesn’t guess — it works from real payloads. It maps fields against actually captured payloads, edits existing webhooks by name or id instead of duplicating them, validates endpoints with a guarded probe (SSRF-protected, secrets always redacted), and verifies the result with a real test delivery. Every operation is also published as a WordPress Ability, so external AI tools (Claude Code, Cursor) can drive the same toolset over the Model Context Protocol (MCP) with scoped API tokens.

The Payload Library

Mapping fields needs an example payload, and until a trigger fires on your site there is nothing to map against — which is worst on the events that are hardest to produce on demand: a refunded order, a cancelled subscription, a deleted user.

The Payload Library closes that gap with hundreds of hook payloads captured on our own test sites — WordPress core, WooCommerce, ACF and the major form plugins — so the agent can work from the real shape of an event your site has never fired. Your own capture always wins the moment the event really fires, and a reference payload is always labelled as one: the trigger panel shows a „WP Webhooks Payload Library” badge naming the plugin build it came off, and every build made from one ends with a test delivery before the webhook can go live.

What a reference payload cannot know is your own keys. Fields inside containers your site defines — a form’s fields, post or order meta, ACF — are never mapped from it; the agent pauses, names the paths, and asks you to fire the event once. Lookups run while Build with AI is on WP Webhooks AI (the free trial or Pro credits) and cost no credits.

The API Docs Library

A language model remembers an API the way it was documented when the model was trained: an old version path, a body envelope that has since changed, a required field it never saw. Build with AI does not build from that memory. When a prompt names a service the library knows — HubSpot, Airtable, Slack, Notion, Stripe, Shopify, OpenAI, Anthropic, Gemini and 300+ more — WP Webhooks AI reads that service’s current reference card on our server and puts it in front of the model before it plans: the exact endpoint and method, how the auth token enters the plan (as a credential step, not a question in chat), the body envelope, request-level flags, and the 4xx responses that come up in practice.

A service nobody has a card for yet is researched on the spot from the vendor’s own documentation — the chat says „Reading …’s API reference for the first time” while it waits, usually under a minute, and the wait costs no credits — and the card is kept for everyone. Every reply built from a card carries a „WP Webhooks API Docs Library” pill naming the service, the operation and the date the reference was verified, linking to the vendor’s page. Available while Build with AI runs on WP Webhooks AI (the free trial or Pro credits); about one credit on the turn that uses a card.

Notifications

Retries handle the flaky minute; Notifications handle the endpoint that stays down at 3 a.m. Get told when a delivery fails, retries, gives up, is skipped, succeeds or recovers — by email, Slack, Discord, Telegram, Microsoft Teams, Google Chat, Mattermost, Pushover, ntfy, SMS and WhatsApp through Twilio, PagerDuty (an incident that opens on failure and resolves on recovery), or any URL as JSON. Rules decide when and where: which attempt, which HTTP codes, which triggers; a quiet time per webhook so a bad hour is one message, not a hundred; hourly or daily digests. Every webhook inherits the site-wide rules, can mute single ones, keep only its own, or switch notifications off. Every message is a template with {{ payload.order.id }}-style placeholders, a field picker, a live preview against your captured payload, a linter — and a Draft with AI button. Channel secrets are encrypted and never shown again. Entirely free. Five-minute setup guide · Feature overview

The engine underneath (free)

  • Turn any WordPress do_action into a first-class automation trigger your CRMs, n8n flows, AI agents, and internal services can consume — every dispatch is an outgoing webhook you fully control
  • Persistent delivery queue with smart retry and exponential backoff — powered by WP-Cron, auto-upgrades to Action Scheduler or System Cron when available, (Pro) External Cron for guaranteed reliability
  • Per-event UUID and ISO 8601 timestamp — enable downstream deduplication
  • Delivery logs with full attempt history, request/response inspection, replay, and bulk retry
  • Code Glue — attach PHP snippets to any webhook+trigger to reshape the payload before dispatch or run side effects after the response, with a preview that runs your code against a real captured payload first. Build with AI can draft, test-run and assign them for you
  • Per-webhook retry limit and backoff strategy (exponential, linear or fixed), each falling back to a site-wide default
  • Synchronous execution mode — fire inline without queue delay
  • Payload mapping — rename, restructure, exclude, and type-cast fields with dot-notation paths
  • Conditional dispatch — filter events by payload field values before dispatch, so a Slack notification or a CRM sync only fires when it should. Build as many rules as you need and group them with AND/OR matching, by hand or by describing them to Build with AI
  • HTTP method, custom headers, and URL query parameters per webhook
  • Dynamic endpoint URLs — {{ field.path }} placeholders resolved against the payload at dispatch time, or the fswa_webhook_url filter if you would rather do it in PHP
  • Webhook Chains — wire 2xx completions to downstream webhooks with full observability
  • Import & Export — move webhooks and chains between sites as portable JSON (triggers, field mapping, conditions and Code Glue snippets included), with strict validation and a per-item result summary on import
  • Markdown descriptions — document what each webhook and chain does inline, with a Write/Preview toggle while editing
  • Notifications — email, Slack, Discord, Telegram, Teams, SMS, PagerDuty and more when a delivery fails, gives up or recovers; rules with filters, quiet times and digests; templated messages the AI can draft
  • Credentials Vault — store reusable auth secrets (Bearer, Basic, API key, custom) encrypted at rest; reference them from webhooks instead of pasting raw Authorization headers. Secrets are write-only over the API — never returned, only a masked hint
  • Activity History — persistent audit log of every admin and API-token action
  • Built-in CF7 and IvyForms integrations — structured payloads, no extra plugins
  • Action Scheduler auto-detection — more reliable delivery on high-traffic sites
  • Fully translatable — the entire admin interface and all server-side strings are internationalized; ships with Polish, Simplified Chinese, and Dutch, and is compatible with WPML and Polylang String Translation
  • Full REST API with scoped API token authentication (read / operational / full / agent) — the agent scope grants full write access for AI assistants while never exposing stored secrets
  • Developer extensibility — 26 filters and 11 action hooks (reference)

Pro features

  • AI credits included — Build with AI runs through the hosted WP Webhooks AI service on every Pro plan: no API keys to create, no provider accounts, a monthly credit allowance that renews automatically, and a live credits counter in the builder. Your own keys and WordPress connectors stay available any time
  • External Cron — replace unreliable visitor-triggered WP-Cron with a managed external pinger, provisioned automatically on license activation. Two modes: plugin queue endpoint (down to 20 s interval, configurable batch size) or WP-Cron endpoint (60 s, covers all WordPress background work). No server crontab or external dashboard — controlled entirely from wp-admin, with a live heartbeat chart and inline error alerts

See pricing and upgrade

Examples

Zrzuty ekranu

Instalacja

  1. Upload the plugin files to the /wp-content/plugins/flowsystems-webhook-actions directory, or install the plugin through the WordPress plugins screen.
  2. Activate the plugin through the 'Plugins’ screen in WordPress.
  3. Navigate to Webhook Actions in the admin menu — it opens on Build with AI.
  4. Connect an AI provider (or use your WordPress 7.0 AI connectors) and describe the integration you want — or skip the AI and configure webhooks manually under the Webhooks tab.

Najczęściej zadawane pytania

Does the AI Builder need an API key? Is it free to use?

No key, and nothing to sign up for. Your first prompt automatically claims 55 free credits — no account, no card, and the only thing the plugin sends is your site address. That is about five agent turns, or roughly two complete automations built end to end, which is enough to find out whether this works for you before committing anything.

When the credits run out you have three ways to carry on, and two of them are free. If your site has an AI provider connected in WordPress (Settings Connectors), the builder uses it with no extra setup. Otherwise bring your own Anthropic, OpenAI or Google key — a free Google AI Studio key gives you Gemini at no cost. Here’s how to get one in two minutes Or move to Pro, which includes a hosted credit pool and no keys at all. Whichever you pick, a site with its own key never spends the free credits.

Is my data safe with the AI Builder?

Yes. Your provider API keys are encrypted in the Credentials Vault and never returned over the API. Stored webhook credentials are never sent to the AI model, and captured payload values whose field names look sensitive (passwords, tokens, keys) are redacted before any prompt is built. The agent’s changes run locally in the plugin — the model only proposes the plan.

Is this plugin free?

Yes. The core plugin is completely free and licensed under GPL. Webhook Actions Pro is an optional paid upgrade that adds two things, both of which run on our infrastructure rather than yours: included AI credits for Build with AI (hosted, no API keys needed) and External Cron (activated automatically on license activation). Everything the plugin does — Code Glue, unlimited AND/OR conditions, per-webhook retry and backoff, dynamic URL templates, and the AI agent that can build all of them for you — is free as of 3.0.0. Learn more

Does it work with WooCommerce, n8n, Make, Zapier, and AI agents?

Yes. Any WordPress or WooCommerce action can be a trigger. The plugin delivers to any HTTP endpoint — n8n, Make, Zapier webhook nodes, internal services, or AI agent APIs. Scoped API tokens let Claude Code, Cursor, or any automation tool read logs, retry deliveries, and toggle webhooks without WordPress credentials.

Is this a Zapier or Make alternative?

For the WordPress half of the job, yes — and it is worth being precise about which half. Zapier, Make and Pabbly are multi-app orchestrators with large connector catalogues and a visual canvas. If your workflow joins several SaaS products that have nothing to do with WordPress, that is what they are for, and this plugin is not an alternative to it.

What it does replace is the metered hop out of WordPress. Rather than spending a task every time an order or a form entry leaves your site, your own server sends it — queued, retried with exponential backoff, and logged with full request and response history. Webhook Chains let one delivery trigger the next on a 2xx response, so a multi-step flow can stay on your own infrastructure. There is no connector catalogue here: you point a webhook at a URL and map the fields.

Plenty of sites run both — this plugin as the unmetered, self-hosted exit from WordPress, with a Zapier or Make node on the far end when a workflow genuinely needs their catalogue.

Does it work with Elementor Forms, WPForms, Forminator, Fluent Forms or Gravity Forms?

Yes. These plugins fire their own WordPress actions when a form is submitted, and Webhook Actions can use any of them as a trigger — so you can send an Elementor Forms or WPForms submission straight to a webhook without a dedicated add-on. Pick the plugin’s submit action in the trigger list, capture a real submission to see the payload, then map the fields you want. Contact Form 7 and IvyForms additionally ship with built-in normalization; the others use the generic trigger path.

Can I send WordPress data to Slack, Google Sheets, Airtable or a CRM?

Yes — any destination that accepts an HTTP request works. For Slack or Discord, paste the incoming-webhook URL they give you and map the payload into the message field. For Google Sheets, Airtable, Mailchimp, HubSpot or Salesforce, either call their API directly or point the webhook at an n8n, Make or Zapier node and let it do the last hop. Nothing here needs a per-service connector, because the plugin speaks plain HTTP.

Do I need extra plugins for Contact Form 7 or IvyForms?

No. Both integrations are built in. When CF7 or IvyForms is active, submissions are automatically normalized into clean JSON payloads — no additional plugins or custom code required.

Can it alert me when a webhook fails?

Yes, for free. Notifications Channels holds where messages go (email, Slack, Discord, Telegram, Teams, Google Chat, Mattermost, Pushover, ntfy, Twilio SMS/WhatsApp, PagerDuty, any URL); Notifications Rules decides when — a failed attempt, a scheduled retry, a delivery that gave up, a skipped event, a success, or a recovery — with filters on the attempt number, HTTP code and trigger, a quiet time per webhook and hourly or daily digests. Each webhook can inherit the site-wide rules, mute some, or have its own. The Sent tab shows every message and its status.

How does retry work?

The dispatcher retries 5xx and 429 responses automatically with exponential backoff. The delay before attempt N is base_delay × 2^N, capped at the maximum delay — so on the defaults (exponential, 30s base, 1 hour cap, 5 attempts) a failing delivery is retried after 60s, 120s, 240s and 480s, and is marked permanently_failed roughly 15 minutes after the first attempt. The 1 hour cap only comes into play if you raise the attempt limit or the base delay. 4xx and 3xx responses are marked permanently_failed immediately — bad payloads are not worth retrying. Override the attempt limit per webhook in the UI, or globally with the fswa_max_attempts filter; the backoff strategy (exponential, linear or fixed) and its base and maximum delays are per-webhook settings too, each falling back to a site-wide default.

Can I access the REST API without a WordPress login?

Yes. Create a token from the API Tokens screen and pass it as X-FSWA-Token: <token> (or Authorization: Bearer). Four scopes available — read, operational, full, and agent (full write access for AI assistants that never exposes stored secrets) — so you can grant exactly the access each integration needs. Full API reference at wpwebhooks.org/webhook-wordpress-plugin-api/

Recenzje

2026-03-05 1 odpowiedź
Solid plugin. Super easy to set up and it just works. If you need reliable webhooks this makes the whole process a lot easier.
2026-02-19 1 odpowiedź
Used it in WooCommerce project, async processing works well and retry logic saved us from silent webhook failures.
Przeczytaj 2 recenzje

Kontrybutorzy i deweloperzy

„Webhook Actions – build automations and integrations with AI help” jest oprogramowaniem open source. Poniższe osoby miały wkład w rozwój wtyczki.

Zaangażowani

Rejestr zmian

For the full release history see wpwebhooks.org/changelog/

3.3.0 — 2026-09-23

  • Added: Notifications. Get told when a delivery fails, retries, gives up, is skipped, succeeds or recovers — by email, Slack, Discord, Telegram, Microsoft Teams (Workflows), Google Chat, Mattermost/Rocket.Chat, Pushover, ntfy, SMS and WhatsApp through Twilio, PagerDuty (an incident that opens on failure and resolves on recovery), or any URL as JSON. Channels keep their secrets encrypted in the vault’s envelope and never return them; each has a „Send test” button
  • Added: rules decide when and where. Site-wide rules apply to every webhook; a webhook can inherit them, mute single ones, keep only its own, or switch notifications off. Filters: which attempt number, which HTTP codes (503, 5xx, 500-504, or no response), out-of-attempts vs not-retryable, trigger name patterns. A per-webhook quiet time and hourly or daily digests keep a noisy site quiet; a site-wide „every success” rule starts with a one-hour quiet time
  • Added: every message is a template. Subject, title, body and a one-liner for SMS use the same {{ path }} placeholders as dynamic URLs, over the webhook, the event, the delivery (attempt, HTTP code, error, next try, log link), the mapped payload, the raw payload ({{ args.0.email }}) and the site, with modifiers such as | truncate:120, | default:"—", | date:"Y-m-d H:i" and | json. A live preview renders against the captured payload or a real delivery, a field picker inserts paths, and a linter flags paths that are not in the payload
  • Added: Draft with AI. The rule editor asks the site’s AI provider to write the message from the captured payload, and Build with AI can add a notification rule to a plan („and ping me on Slack if it fails”) — the same linter feeds unknown paths back to the model. New abilities: list_notification_channels, list_notification_rules, create_notification_rule, update_notification_rule, test_notification_rule — also reachable over MCP
  • Added: a Sent tab with every notification, its status and a resend button; a bell on delivery-log rows that produced notifications; a health-bar warning when a channel keeps failing
  • Added: the fswa_delivery_event action fires at every delivery state change with the full context (webhook, trigger, attempt, HTTP code, error, payloads), so your own code can react too; fswa_notification_message filters a rendered message before it is sent; fswa_notification_channel_drivers adds a channel type; fswa_notification_http_args tunes the outgoing request; fswa_notification_inline_send decides whether a synchronous webhook’s notifications go out at the end of the same request (the default, so they never wait for a cron that may not run) or through cron like a queued delivery’s
  • Changed: builds export a webhook’s notification rules (channels never travel); on import a rule whose channels do not exist here is created switched off and listed in the import problems
  • Changed: database schema 2.5.0 adds the notification tables and two webhook columns