PartnerPage API
    • Introduction
    • Authentication
    • Object Overview
    • Verify and handle webhook deliveries
    • Directory webhook events and payloads
    • Partner lead webhook event
    • Directory
      • Forms
        • Get all custom forms
        • Get all currency field options
        • Get all contact request form
        • Get default contact request form
        • Create a cotact request custom form
        • Delete a contact request custom form
      • Callouts
        • Get all callouts
        • Get a callout
        • Create a new callout
        • Update a directory callout
        • Delete a directory callout
      • Badges
        • Get all badges
        • Get a badge
        • Create a badge
        • Update a badge
        • Delete a badge
      • Certifications
        • Get all certifications
        • Get a certification
        • Create a certification
        • Update a certification
        • Delete a certification
      • Filters
        • Filter Options
          • Get all filter options
          • Get a filter option
          • Create a filter option
          • Update a filter option
          • Deletes a filter option
        • Get all filters
        • Get a filter
        • Create a filter
        • Update a filter
        • Deletes a filter
        • Get all internal filters
        • Get all filters for external directory
      • Filter Maps
        • Get all filter option mappings
        • Get a filter option mapping
        • Create a new filter option mapping
        • Update a filter option mapping
        • Delete a filter option mapping
        • Get all filter option mappings for external directory
      • Matchmaking
        • Get all matchmaking requests
      • Tiers
        • Get all tiers
        • Get a tier
        • Create a tier
        • Update a tier
        • Delete a tier
        • Get all entries assigned to an specific tier
        • Assign or Unassign entries to an specific tier
      • Verifications
        • Get all verifications
        • Get a verification
        • Create a verification
        • Update a verification
        • Delete a verification
      • Settings
        • Retrieve the settings for a directory
        • Update the settings for a directory
      • List directories
        GET
      • Get a directory
        GET
      • Create a directory
        POST
      • Update a directory
        PATCH
    • Entry
      • App Entry
        • Callouts
          • Get all callouts
          • Get an entry callout
          • Create a new callout
          • Update a callout
          • Delete a callout
        • Get an app entry
        • Create new app entry
        • Update app entry
        • Delete a app entry
        • Update the recommended order of an app entry
      • Partner Entry
        • Badges
          • Get all badges
          • Get a badge
          • Create a badge
          • Update a badge
          • Delete a badge
        • Callouts
          • Get all callouts
          • Get a callout
          • Create a callout
          • Update a callout
          • Delete a callout
        • Certifications (General)
          • Get all certifications
          • Get a certification
          • Create a certification
          • Update a certification
          • Delete a certification
        • Certifications (Industry)
          • Get all industry certifications
          • Get an industry certification
          • Create an industry certification
          • Update an industry certification
          • Delete an industry certification
        • Certifications (Segment)
          • Get all segment certifications
          • Get a segment certification
          • Create a segment certification
          • Update a segment certification
          • Delete a segment certification
        • Client
          • Get all Clients
          • Get a client
          • Create a client
          • Update a client
          • Delete a client
        • Keywords
          • Get all keywords
          • Get a keyword
          • Create a keyword
          • Update keyword
          • Delete a keyword
        • Locations
          • Get all location
          • Get a location
          • Create a location
          • Update a location
          • Delete a location
        • Media
          • Get all media
          • Get a media
          • Create a media
          • Update a media
          • Delete a media
        • Resources
          • Internal
            • Get all Internal resources
            • Get an internal resource
            • Create an internal resource
            • Update an internal resource
            • Delete an internal resource
          • Get all resouces
          • Get a resource
          • Create a resource
          • Update a resource
          • Delete a resource
        • Special Offers
          • Get all special offer
          • Get a special offer
          • Create a special offer
          • Update a special offer
          • Delete a special offer
        • Testimonials
          • Internal
            • Get all internal testimonial
            • Get an internal testimonial
            • Create an internal testimonial
            • Update an internal testimonial
            • Delete an internal testimonial
          • Get all testimonials
          • Get a testimonial
          • Create a testimonial
          • Update a testimonial
          • Delete a testimonial
        • Use Cases
          • Internal
            • Get all internal use cases
            • Get an internal use cases
            • Create an internal use case
            • Update an internal use case
            • Delete an internal use case
          • Get all use cases
          • Get a use case details
          • Create a use case
          • Update a use case
          • Delete a use case
        • Verifications
          • Get all verifications
          • Get a verification
          • Create a verification
          • Update a verification
          • Delete a verification
        • Contact Information
          • Return entry contact information
        • Invite
          • Get organization matches for partner invite
          • Get partner entry owner organization invite
          • Get partner entry owner user invites
          • Invite organization to own partner entry
          • Invite users to partner entry ownership
        • Entry Edits Approval Flow
          • Partner Entry Submit Review
          • Partner Entry Approve Review
          • Partner Entry Reject Changes
          • Partner Entry Discard Review
        • Get all partner entry
        • Get a partner entry
        • Create a partner entry
        • Update a partner entry
        • Delete a partner entry
        • Bulk upsert partner entries
        • Update the recommended order of a partner entry
      • Get all entries
        GET
    • Contact Request
      • Attachment
        • List contact request attachments
        • Create contact request attachment
        • Delete contact request attachment
      • Get all contact requests
        GET
      • Get a contact request
        GET
      • Create a new partner contact request
        POST
    • Matchmaking
      • Get all matchmaking requests
      • Get a matchmaking request
      • Create a new matchmaking request for a directory
      • Get all partners assigned to matchmaking requests
      • Assign an owner to a matchmaking request
      • Set partners to a matchmaking request
    • Review
      • directory-review-list
      • directory-review-detail
      • directory-review-create
      • Update a review
      • Delete a review
      • reviewsDirectoryExportRetrieve
    • contact-requests
      • Close a contact request
      • Send a reminder to the partner about a contact request
    • directories
      • List contact request routing sources
      • Get the webhook signing secret
      • Rotate the webhook signing secret
    • entries
      • Cancel a pending partner contact invitation
    • matchmaking-requests
      • Close a matchmaking request
      • Reopen a matchmaking request
    • organizations
      • Get the organization's webhook
      • Create the organization's webhook
      • Update the organization's webhook
      • Delete the organization's webhook
      • List the organization's webhook deliveries
      • Get one webhook delivery
      • Rotate the organization's webhook signing secret

    Verify and handle webhook deliveries

    This guide is for the person building the receiving end of a PartnerPage webhook. It applies to both kinds: directory webhooks, set up by the company that runs a directory, and the partner lead webhook, set up by a partner. Both send the same request with the same headers.
    Setting a webhook up in the dashboard is covered in the Help Center: directory webhooks and the partner lead webhook.

    The request we send#

    Every delivery is an HTTPS POST to your URL with a JSON body encoded as UTF-8. It is sent from PartnerPage's servers within seconds of the event.
    HeaderValue
    Content-Typeapplication/json; charset=utf-8
    X-Event-TypeThe event name, for example contact_request_created
    X-Webhook-SignatureHMAC-SHA256 of the raw request body, hex encoded in lowercase, keyed with your signing secret
    X-Webhook-Delivery-IdAn id for this delivery. If the same delivery is ever sent again, it carries the same id
    Conventions used in every payload:
    Ids are UUIDs, sent as strings.
    created timestamps are in UTC, formatted YYYY-MM-DD HH:MM.
    Fields with no value are null.
    We may add fields over time. Ignore fields you do not recognise instead of rejecting the request.

    Verify the signature#

    Checking the signature proves the request came from PartnerPage and was not changed on the way.
    Where to find your signing secret
    Directory webhooks: your directory, then Webhooks, then Events, on the Signing secret card. Each directory has its own secret.
    Partner lead webhook: Settings, then Developers, on the Lead webhook card. Each organization has its own secret.
    How to check it
    1.
    Read the raw bytes of the request body, before any JSON parsing.
    2.
    Compute the HMAC-SHA256 of those bytes, using your signing secret as the key, and encode the result as lowercase hex.
    3.
    Compare it with the X-Webhook-Signature header using a constant-time comparison.
    4.
    Reject the request if they differ.
    Python:
    Node.js:
    In frameworks that parse JSON automatically (Express with express.json(), Django REST Framework, Rails), sign the original body bytes, not a re-serialised version of the parsed object.
    Rotating the secret. Clicking Regenerate in the dashboard replaces the secret immediately. There is no overlap period: the next delivery is signed with the new secret, so update your receiver right after regenerating.
    Directory showing "Not in use yet". A directory that used webhooks before per-directory secrets existed is still signed with an older shared secret until someone clicks Regenerate. Signatures will not match the secret on the card until then.
    Also use a URL nobody can guess. Include a long random token in the path of your URL and reject requests without it. n8n, Zapier and Make webhook URLs already include one.

    Reply to a delivery#

    Reply with any 2xx status within 15 seconds.
    The body of your reply is ignored. Its first 255 characters are stored in the delivery log, which helps when debugging.
    Do slow work after replying: accept the request, queue it, return 200.
    Point us at the final address. The partner lead webhook does not follow redirects.

    Duplicate deliveries#

    We make sure an event is delivered even if our servers restart at the moment it is being sent. The trade-off is that, rarely, the same delivery can reach you twice. To handle that:
    1.
    Read X-Webhook-Delivery-Id on every request.
    2.
    If you have already processed that id, reply 200 and do nothing else.
    3.
    Otherwise process the event and remember the id. Keeping ids for 24 hours is plenty.
    In n8n, Zapier or Make, store the id (a data table, a sheet, Redis) and add an "already seen?" check as the first step of the flow.

    Failed deliveries#

    A delivery that times out, cannot connect, or receives a status outside 2xx is recorded as failed and is not retried. The record itself is never lost: it stays in the PartnerPage dashboard, and the ids in the payload let you look it up.
    Where to see deliveries:
    Directory webhooks: Webhooks, then Logs. Use the errors filter to show only failures.
    Partner lead webhook: the Deliveries card under Settings, then Developers. Use the Errors view.
    Statuses recorded when your server never answered:
    Recorded statusMeaning
    408Your endpoint did not answer within 15 seconds
    503We could not connect (DNS, TLS or network error)
    500Another error while sending, for example a URL that resolves to a private network address
    Any other status is the one your endpoint returned.

    Order of events#

    Events for the same record can arrive close together, for example a contact_request_created followed by a contact_request_updated. Do not assume they arrive in order. Treat the state and project_status fields in the payload as the source of truth.

    Troubleshooting#

    No delivery recorded at all. For directory webhooks, check that a subscription exists for that event trigger and that the action happened in this directory. For the partner lead webhook, check that the webhook is switched on; if it is, the directory owner may have switched partner lead delivery off for that directory.
    408. Reply first, process later.
    503. The URL must resolve publicly and present a valid TLS certificate. Localhost, private networks and self-signed certificates do not work. Use a tunnel such as ngrok while developing.
    401 or 403. Your endpoint is asking for authentication. We send no authentication header. Put a token in the URL and verify the signature instead.
    404 or 405. Check the path and that the endpoint accepts POST.
    Signature does not match. Make sure you sign the raw body, that the secret was copied in full, and that nobody regenerated it since. For a directory, check whether the Signing secret card says "Not in use yet".

    Payloads#

    Directory webhooks: Directory webhook events and payloads lists the eight events and every field.
    Partner lead webhook: Partner lead webhook event shows the one payload it sends.
    Modified at 2026-10-05 17:34:10
    Previous
    Object Overview
    Next
    Directory webhook events and payloads
    Built with