How forwarding works
- You configure your appβs webhook URL in Environment Settings > Webhook URLs.
- You register the integrationβs Nango webhook URL in the providerβs developer portal. Find it in Integrations > [Integration] > Webhooks.
- The provider sends a webhook to Nango.
- Nango runs the provider-specific routing logic and tries to map the event to one or more Nango connections.
- Nango forwards the payload to your appβs webhook URL and signs the request like other Nango webhooks.
Forwarded payloads
When Nango can attribute the webhook to a connection, your app receives a Nango wrapper:Headers and signatures
Nango forwards safe provider headers when possible, excluding headers that should not be replayed such asauthorization, cookie, host, content-length, content-type, user-agent, and similar transport-sensitive headers.
Every forwarded webhook is signed with the same headers used by other Nango webhooks:
X-Nango-Hmac-Sha256X-Nango-Signaturefor backwards compatibility
Unverified webhooks
Nango verifies the provider signature before forwarding whenever the provider signs its webhooks and the integration has the secret to check it. When Nango knows it skipped that check, for example because the webhook secret is not set on the integration, it still forwards the webhook but flags it:- The
X-Nango-Webhook-Unverified: trueheader is set on the forwarded request, including raw payloads. - The Nango wrapper includes
"unverified": true.
When to use forwarding
Use forwarding when:- Your app already has webhook handling logic.
- You want app code to decide what to do with the provider event.
- You need Nango to attribute the event to a connection when possible.
- You want webhook delivery logs and retries without running Nango function code.
Configure forwarding
1
Configure your app webhook URL
In Nango, open Environment Settings > Webhook URLs and add your appβs endpoint.Nango sends forwarded webhooks to the same URLs used for auth, sync, and async action webhooks.
2
Register the provider webhook URL
In the integration page, copy the Nango webhook URL from Integrations > [Integration] > Webhooks and register it in the providerβs developer portal.Some providers use one global webhook registration. Others require one webhook registration per connected account. Provider-specific docs explain the required setup.
3
Handle both payload shapes
If the payload has
"type": "forward", read connectionId, providerConfigKey, and payload.If the payload does not have "type": "forward", handle it as the raw provider payload. This can happen when the provider event cannot be attributed to a Nango connection.For agents
For agents
When implementing webhook forwarding, first find the provider-specific Nango webhook guide. Confirm whether the provider routes automatically or requires embedding the Nango connection ID, tenant ID, team ID, installation ID, or another identifier in the provider webhook subscription.Implement signature verification with
X-Nango-Hmac-Sha256, then branch on whether the incoming body has type: "forward". Store and use connectionId only when it is present.Providers that do not sign webhooks
Affinity, Fillout and ShipStation do not sign their webhooks, so Nango checks a secret you choose for each connection instead. Nango rejects a webhook unless it carries the secret of the connection it is routed to.- Generate a random secret of at least 16 characters per connection and store it as
webhookSecretin that connectionβs metadata. - Send that connectionβs secret with every webhook registered for it, in the
X-Nango-Webhook-Secretheader or, when the provider only lets you set a URL, as anangoWebhookSecretquery param on the Nango webhook URL.
nangoConnectionId=<CONNECTION-ID> to the webhook URL registered in each end userβs Affinity instance.
The secret usually sits in your end userβs own webhook config, where their admins can see it. Because it belongs to one connection, it only lets them send events for their own connection.
Salesforce events come from an Apex trigger you install in each connected org, and use the same per-connection secret. See How to set up webhooks with Salesforce on Nango.