
Sent EventTrigger
CertifiedTrigger a flow from a signed Sent webhook
Sent EventTrigger
Trigger a flow from a signed Sent webhook
Receives Sent events at Kestra's native webhook URL. It requires X-Webhook-ID, X-Webhook-Timestamp, and X-Webhook-Signature; verifies HMAC-SHA256 in constant time before parsing and filtering the event. Kestra 1.3 supplies the body as a string: UTF-8 bytes are reconstructed without JSON reserialization. Non-UTF-8 charset declarations and U+FFFD replacement characters are rejected to prevent lossy decoding from changing signed bytes. Register the generated HTTPS URL manually in Sent.
type: io.kestra.plugin.sent.triggers.EventTriggerExamples
Handle signed inbound-message events
id: sent_inbound_events
namespace: company.messaging
tasks:
- id: log_event_identifiers
type: io.kestra.plugin.core.log.Log
message: "Sent event {{ trigger.event }} with dedupe key {{ trigger.dedupeKey }}"
triggers:
- id: sent_webhook
type: io.kestra.plugin.sent.triggers.EventTrigger
key: "{{ secret('SENT_WEBHOOK_URL_KEY') }}"
signingSecret: "{{ secret('SENT_WEBHOOK_SIGNING_SECRET') }}"
events:
- message.received
Properties
key *string
1256The unique key that will be part of the URL.
The key is used for generating the webhook URL.
::alert{type="warning"} Make sure to keep the webhook key secure. It's the only security mechanism to protect your endpoint from bad actors, and must be considered as a secret. You can use a random key generator to create the key. ::
signingSecret *string
Sent signing secret
Webhook secret returned by Sent, including the whsec_ prefix. Store it as a Kestra secret.
allowConcurrent boolean
falseSpecifies whether a trigger is allowed to start a new execution even if a previous run is still in progress.
events array
["message.received"]Events
Event names or parent fields to accept. Use * to accept every verified event.
fetchType string
FETCHNONEFETCHSTOREWhat the trigger does with the body of the webhook request.
FETCH: the body reaches the flow on thebodyoutput. A JSON body is deserialized, a binary one is base64-encoded. This is the default, and how a webhook has always behaved.STORE: the body is streamed into Kestra's internal storage as it is received, and the flow reaches it through theurioutput. Nothing of it travels through the execution, so this is the option to use for a large or binary payload - but note that a condition on the trigger can no longer read the body.NONE: the body is read off the connection and dropped. Use it for a caller whose payload the flow does not need.
This only concerns the body of a request. The file parts of a multipart/form-data request are always stored in the internal storage and exposed on parts, whatever this property is set to, as a file part has no meaningful representation inside an execution.
inputs object
The inputs to pass to the triggered flow
stopAfter array
CREATEDSUBMITTEDRUNNINGPAUSEDRESTARTEDKILLINGSUCCESSWARNINGFAILEDKILLEDCANCELLEDQUEUEDRETRYINGRETRIEDSKIPPEDBREAKPOINTRESUBMITTEDList of execution states after which a trigger should be stopped (a.k.a. disabled).
tolerance string
PT5MReplay tolerance
Maximum absolute difference from X-Webhook-Timestamp. Must be positive and at most one hour; Sent recommends five minutes.
when string
trueA condition that determines whether the trigger should run.
A Pebble expression evaluated at trigger time. The trigger fires only when the expression evaluates to a truthy value (true, a non-empty string, a non-zero number). Use this to gate trigger execution on dynamic runtime values such as execution labels, flow variables, or environment conditions.
Outputs
dedupeKey string
Dedupe key
Payload-derived candidate key. Persist it atomically in a shared store if the flow needs cross-execution deduplication.
event string
Event name
Granular Sent event name, such as message.delivered.
field string
Event field
Parent Sent event family, such as message or templates.
payload object
Event payload
Event-specific payload from the verified request. It may contain phone numbers or message content; avoid logging it wholesale.
timestamp string
Event timestamp
ISO 8601 event-creation timestamp from the signed body.
webhookId string
Webhook ID
Sent webhook configuration UUID. This is not a unique delivery ID.