1. Prepare the endpoint
Create an HTTPS URL that accepts JSON POST requests. Deliveries include article ID, title, slug, HTML, Markdown, images, metadata and event. Your receiver should distinguish creation from update using the article ID.
2. Verify the signature
Configure the same secret on both sides. X-SpotgrowAI-Signature contains t={timestamp},v1={signature}. The signature is HMAC-SHA256 of timestamp + "." + the original body. Verify it before processing JSON, apply a time window and deduplicate by X-SpotgrowAI-Delivery.
3. Test and acknowledge delivery
Save the webhook and run the wizard test. After accepting a delivery, return a 2xx status and a JSON object, for example {"success":true}. An empty body, a redirect or {"success":false} is treated as an error. Review delivery history and configure article removal only if your receiver implements that event.