AI Automation with n8n, Make and ZapierAPIs, webhooks, LLMs and MCP · Lesson 9 of 17

Webhooks and APIs: connecting anything

Article · 16 min · 9 min lecture

Video lecture

Webhooks and APIs: connecting anything

13 chapters · about 9 min · full transcript

Coming soon

Chapter 1 of 13

Webhooks and APIs

  • When connectors aren't enough
  • API essentials
  • Secure webhooks
  • Reliable API calls

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

When the built-in app isn't enough

Every platform has thousands of prebuilt integrations, but sooner or later you need an endpoint the connector doesn't support, a new app with no connector, or your own internal system. Then you use HTTP APIs and webhooks directly: the HTTP Request node (n8n), HTTP module (Make) or Webhooks by Zapier / API request actions (Zapier).

API essentials in ten lines

  • Endpoint: a URL such as https://api.example.com/v1/contacts.
  • Method: GET (read), POST (create), PUT/PATCH (update), DELETE.
  • Headers: metadata such as Content-Type: application/json and Authorization.
  • Body: JSON payload for POST/PUT/PATCH.
  • Query parameters: ?page=2&limit=100.
  • Status codes: 2xx success; 400 bad request; 401/403 auth problems; 404 not found; 409 conflict; 422 validation; 429 rate limited; 5xx server errors.
  • Authentication: API keys (header or query), Bearer tokens, OAuth 2.0 (user-authorized access with refresh tokens), Basic auth, HMAC signatures.
  • Pagination: page/limit, offset, or cursor (next_cursor) patterns.
  • Rate limits: requests per second/minute; respect Retry-After headers.
  • Docs: always read the API reference and test with a tool like curl or an API client first.

Webhooks: APIs in reverse

A webhook is the source app calling your URL when something happens. Your automation platform gives you that URL (n8n Webhook node, Make custom webhook, Zapier Catch Hook).

Security essentials for incoming webhooks:

  1. Verify signatures: many providers sign payloads with HMAC (for example Stripe, Shopify, GitHub, and many others). Compute the signature over the raw body with your secret and compare in constant time.
  2. Check timestamps to reject replayed requests.
  3. Use secret, unguessable URLs and rotate them if leaked; do not rely on obscurity alone.
  4. Respond fast (2xx within a few seconds) and process asynchronously; providers retry on timeouts, which can create duplicates.
  5. Be idempotent: providers can deliver the same event more than once; store event IDs and ignore repeats.

Hands-on: verify an HMAC-signed webhook (Python)

A small verification service you can run in front of any platform, or adapt in a code step:

import hmac, hashlib, os, time
from fastapi import FastAPI, Request, HTTPException

app = FastAPI()
SECRET = os.environ["WEBHOOK_SECRET"].encode()
SEEN = set()  # use a database or Redis in production

@app.post("/hooks/orders")
async def orders(request: Request):
    raw = await request.body()
    sig = request.headers.get("X-Signature", "")
    ts = request.headers.get("X-Timestamp", "0")
    if abs(time.time() - int(ts)) > 300:
        raise HTTPException(401, "stale")
    expected = hmac.new(SECRET, f"{ts}.".encode() + raw, hashlib.sha256).hexdigest()
    if not hmac.compare_digest(expected, sig):
        raise HTTPException(401, "bad signature")
    event = await request.json()
    if event["id"] in SEEN:
        return {"ok": True, "duplicate": True}
    SEEN.add(event["id"])
    # forward to n8n/Make/Zapier, or enqueue for processing
    return {"ok": True}

Header names and signing formats differ by provider; follow each provider's documentation exactly (some sign only the body, some include a timestamp, some base64-encode).

Calling APIs well from automations

  • Store credentials in the platform's credential manager, never in plain fields or code.
  • Handle pagination with loops until no next page (n8n's HTTP Request node has built-in pagination options; Make supports pagination in some modules and via repeaters; Zapier code or looping).
  • Respect rate limits: batch, add waits, use sequential processing.
  • Parse errors meaningfully: map 4xx to data problems (fix and alert), 429/5xx to transient problems (retry with backoff).
  • Log request IDs returned by APIs for support tickets.

Worked example: connecting a Pakistani courier API with no connector

A Lahore e-commerce brand needs to create shipments with a local courier that offers a REST API but no n8n/Make/Zapier app.

  • n8n: HTTP Request node, POST /shipments, header auth credential, JSON body mapped from the order; on 422, route to a Slack alert with the validation message; on 429/5xx, retry with wait.
  • The courier sends status updates to a webhook; the n8n Webhook node receives them, verifies a shared-secret header, updates the order in Shopify and sends a WhatsApp template update to the customer (opted-in).
  • Tracking numbers are stored against order IDs to keep updates idempotent.

Test before you automate

curl -sS -X POST "https://api.example-courier.pk/v1/shipments" \
  -H "Authorization: Bearer $COURIER_API_KEY" -H "Content-Type: application/json" \
  -d '{"order_ref":"SO-1042","city":"Lahore","cod_amount":4500,"phone":"+923001234567"}'

If it works in curl, it will work in your platform's HTTP step with the same method, headers and body.

Pitfalls

  • Accepting unsigned webhooks from payment or order systems.
  • Processing heavy work before responding, causing provider retries and duplicates.
  • Hard-coding API keys in code steps or URLs.

Measuring success

Track webhook signature failures (should be zero except attacks or misconfiguration), duplicate events ignored, API error rates by class (4xx vs 429/5xx), and the time from event to processed record.

Key takeaways

  • When connectors fall short, use HTTP APIs: endpoints, methods, headers, JSON bodies, status codes, auth, pagination and rate limits.
  • Webhooks are the source app calling your URL; verify HMAC signatures over the raw body, check timestamps, respond fast and dedupe event IDs.
  • Store credentials in the platform vault, paginate fully, respect rate limits, and treat 4xx (fix) differently from 429/5xx (retry with backoff).
  • Test every API call with curl first, then recreate it in the platform's HTTP step.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. An API returns HTTP 429. What should your automation do?
  2. Why must webhook signatures be computed over the raw request body?
  3. A provider sometimes delivers the same order event twice. What prevents duplicate processing?

Put it into practice

Pick an app with an API but no connector on your platform. Make one successful curl call, recreate it in an HTTP step, and add handling for 422 (alert) and 429 (retry).

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.