Skip to main content
You can configure webhooks from ELT pipelines running in Peliqan, to receive events when pipelines completed, failed etc. This is useful in combination with embedding and the Partner API, to integrate Peliqan’s ELT connectivity into your own platform.

Configuration

Navigate to Settings > API Token & Webhooks > Outbound Webhooks to set up your endpoint to receive webhook events from Peliqan pipelines. image Generate a strong secret:
Subscriptions: Event subscriptions default to all events. You can restrict to a specific subset as well in the UI

Event Types

Connection Events

Fired when data connections are created or deleted. These use a slightly different payload shape - see the Payload section below.

Pipeline Events

Fired by Peliqan’s pipeline runner as a sync progresses from start to a terminal state. Typical event sequence for a normal scheduled run: pipeline_run_started > pipeline_run_completed

Payload

Every webhook event sends a JSON body with the following shape:

HTTP Headers

Every request includes the following headers:

Signature Verification

When a signing secret is configured, Peliqan computes:
canonical_json is the body serialized with keys sorted alphabetically, compact (no extra whitespace). The timestamp is included in the signed string for replay protection - reject requests where X-Peliqan-Timestamp is more than 300 seconds old.

Python

Node.js

Response & Retry

Your endpoint must return a 2xx status code within 10 seconds. Any non-2xx response or network error (connection refused, DNS failure, TLS error, timeout) is treated as a failure. Each event gets up to 4 delivery attempts with exponential backoff: All 4 attempts use the same WebhookCall log row - the attempt counter increments on each retry so you can see the full history in Settings > Webhooks > Call Log. If all 4 attempts fail, the event is permanently marked failed and the account’s consecutive failure counter increments by 1. Auto-disable: After 5 consecutive events each exhausting all retries, Peliqan:
  1. Sets webhook_disabled_at on the account - all further webhook dispatches are skipped immediately (no HTTP calls made)
  2. Sends an alert email to the account’s configured alert recipients
  3. Preserves your URL and secret - nothing is cleared
image Re-enable via Settings > API Token & Webhooks > Outbound Webhooks > Re-enable. Any single successful delivery resets the consecutive failure counter to 0.
SSRF protection: In production, Peliqan uses the advocate library to block webhook URLs that resolve to private or reserved IP ranges (RFC 1918, loopback, link-local, etc.). These are rejected immediately without a network call and logged as “Blocked - the webhook URL points to a private or reserved IP address”.
Call log retention: The most recent 500 WebhookCall records are kept per account. Older entries are trimmed automatically after each delivery.

Idempotency

Retries and the occasional duplicate delivery mean your endpoint may receive the same event more than once. Use these keys to deduplicate or perform idempotent upserts on your side.

Example: Simple Webhook Endpoint (Python)

How to test
  1. Create a webhook endpoint in Peliqan
  2. Update the URL and secret in the Settings > API Token & Webhooks > Outbound Webhook
  3. Trigger an event (e.g., run a pipeline)
  4. Check logs to confirm:
  • Signature verification passes
  • Event payload is received correctly