Sent EventTrigger

Sent EventTrigger

Certified

Trigger a flow from a signed Sent webhook

Receives Sent events at Kestra's native webhook URL. It requires X-Webhook-ID, X-Webhook-Timestamp, and X-Webhook-Signature; verifies HMAC-SHA256 in constant time before parsing and filtering the event. Kestra 1.3 supplies the body as a string: UTF-8 bytes are reconstructed without JSON reserialization. Non-UTF-8 charset declarations and U+FFFD replacement characters are rejected to prevent lossy decoding from changing signed bytes. Register the generated HTTPS URL manually in Sent.

yaml
type: io.kestra.plugin.sent.triggers.EventTrigger

Handle signed inbound-message events

yaml
id: sent_inbound_events
namespace: company.messaging

tasks:
  - id: log_event_identifiers
    type: io.kestra.plugin.core.log.Log
    message: "Sent event {{ trigger.event }} with dedupe key {{ trigger.dedupeKey }}"

triggers:
  - id: sent_webhook
    type: io.kestra.plugin.sent.triggers.EventTrigger
    key: "{{ secret('SENT_WEBHOOK_URL_KEY') }}"
    signingSecret: "{{ secret('SENT_WEBHOOK_SIGNING_SECRET') }}"
    events:
      - message.received
Properties
Min length1
Max length256

The unique key that will be part of the URL.

The key is used for generating the webhook URL.

::alert{type="warning"} Make sure to keep the webhook key secure. It's the only security mechanism to protect your endpoint from bad actors, and must be considered as a secret. You can use a random key generator to create the key. ::

Sent signing secret

Webhook secret returned by Sent, including the whsec_ prefix. Store it as a Kestra secret.

Defaultfalse

Specifies whether a trigger is allowed to start a new execution even if a previous run is still in progress.

SubTypestring
Default["message.received"]

Events

Event names or parent fields to accept. Use * to accept every verified event.

DefaultFETCH
Possible Values
NONEFETCHSTORE

What the trigger does with the body of the webhook request.

  • FETCH: the body reaches the flow on the body output. A JSON body is deserialized, a binary one is base64-encoded. This is the default, and how a webhook has always behaved.
  • STORE: the body is streamed into Kestra's internal storage as it is received, and the flow reaches it through the uri output. Nothing of it travels through the execution, so this is the option to use for a large or binary payload - but note that a condition on the trigger can no longer read the body.
  • NONE: the body is read off the connection and dropped. Use it for a caller whose payload the flow does not need.

This only concerns the body of a request. The file parts of a multipart/form-data request are always stored in the internal storage and exposed on parts, whatever this property is set to, as a file part has no meaningful representation inside an execution.

The inputs to pass to the triggered flow

SubTypestring
Possible Values
CREATEDSUBMITTEDRUNNINGPAUSEDRESTARTEDKILLINGSUCCESSWARNINGFAILEDKILLEDCANCELLEDQUEUEDRETRYINGRETRIEDSKIPPEDBREAKPOINTRESUBMITTED

List of execution states after which a trigger should be stopped (a.k.a. disabled).

DefaultPT5M

Replay tolerance

Maximum absolute difference from X-Webhook-Timestamp. Must be positive and at most one hour; Sent recommends five minutes.

Defaulttrue

A condition that determines whether the trigger should run.

A Pebble expression evaluated at trigger time. The trigger fires only when the expression evaluates to a truthy value (true, a non-empty string, a non-zero number). Use this to gate trigger execution on dynamic runtime values such as execution labels, flow variables, or environment conditions.

Dedupe key

Payload-derived candidate key. Persist it atomically in a shared store if the flow needs cross-execution deduplication.

Event name

Granular Sent event name, such as message.delivered.

Event field

Parent Sent event family, such as message or templates.

Event payload

Event-specific payload from the verified request. It may contain phone numbers or message content; avoid logging it wholesale.

Event timestamp

ISO 8601 event-creation timestamp from the signed body.

Webhook ID

Sent webhook configuration UUID. This is not a unique delivery ID.