Webhook Settings

A webhook is a dedicated intake address used when another program automatically sends files to a designated folder in SpaceBuilder. For example, files generated by a scanner, a business system, or an automation program can be saved to a folder without any human intervention.

On this page, admins configure the server-wide scope and limits for webhook usage. For how to create a webhook on an actual folder and use its intake address, see Using Folder Webhooks.


Before You Configure

  • To call a webhook from outside, you need an address that can reach SpaceBuilder.
  • The webhook address includes a secret value used for authentication. Share the full address only with the admin and the person responsible for the connecting program.
  • Using HTTPS is recommended when exposing it to the internet.
  • The larger the files received, the more the server's memory and storage usage will increase.

Webhook Policy Settings

Webhook usage settings

In the admin settings, choose who can use the webhook feature and at what security level.

ItemDescription
Enable inbound webhook featureTurns on the server's webhook receiving feature. If turned off, files cannot be received even at existing webhook addresses.
Allow users to issue API keysLets regular users create and manage webhook intake addresses on folders themselves.
Allow webhooks on personal foldersAllows webhooks to be created not only on team folders but also on users' personal folders. Enable this when files need to be received into personal folders.
Enforce webhook signature verificationApplies additional signature verification to webhooks that are newly created or have their secret rotated. This is a security feature used when the calling program supports HMAC signatures, and it is off by default.

Capacity and Request Limit Settings

Configure the size and request rate a webhook can receive at one time. In most environments, the default values are sufficient.

ItemDefaultDescription
Maximum payload size8 MBThe total combined size of the file and request information a webhook can receive at once. This is the server default and can be increased when larger files need to be received.
Request rate limit5 per secondLimits requests from arriving too frequently in a short period. Adjust this value only when legitimate requests are being throttled.

Payload refers to the entire content delivered via the webhook, combining the file and the request information. Because it includes information beyond just the file, the displayed size may be slightly larger than the actual file.

If the configured size is exceeded, the file is not saved and a 413 Request Entity Too Large response is returned. For environments that frequently transfer large files, the standard file upload method is more suitable.

Increasing the Size Receivable at Once

To receive files larger than 8 MB via webhook, make the following changes.

  1. In the admin screen, open Service Configuration and go to the Webhook section.
  2. Enter the required size in the Maximum Payload Size field.
  3. Select the MB or GB unit to the right of the input field.
  4. Save the settings.
  5. Verify the transfer with a small file first before sending the actual file.

For example, to receive files up to 20 MB, enter 20 and select MB as the unit. The range the server supports is 1 KB–1 GB.

If you're exposing the webhook to the internet, also configuring request limits in Cloudflare or Nginx can help filter out abnormally high volumes of requests before they reach the server.

  1. Turn on Enable Inbound Webhook Feature.
  2. Turn on Allow Users to Issue API Keys only if users need to create webhooks themselves.
  3. Turn on Allow Webhooks on Personal Folders only if you need to receive files into personal folders.
  4. Use the default values for capacity and request limits.
  5. Save the settings, then create a webhook on the folder you intend to use.
  6. Send a small test file first to verify the storage location and permissions.

Troubleshooting

SymptomWhat to Check
Cannot receive filesCheck whether the inbound webhook feature and user-issue permission are enabled.
401 responseCheck whether the webhook address's secret or signature headers are correct.
403 responseCheck whether personal folder access is allowed and whether the target folder permissions are correct.
409 responseCheck whether the webhook is paused or conflicts with a same-name file handling policy.
413 responseCheck whether the total request size exceeds the maximum payload size.
Server slows down after receiving filesLower the payload size and request rate, and check whether OCR/document conversion tasks are piling up.