Webhooks

Send card events out, and turn JSON into cards.

Outgoing webhooks post signed JSON to your endpoint when cards and sprints change. Incoming URLs create a card from anything that can send a POST.

Outgoing webhooks

In Project settings → Integrations → Webhooks, an admin adds an HTTPS endpoint, picks the events it receives and whether they come from every board or one.

  • A card is created
  • A card moves to another column
  • A card is finished
  • A card is assigned
  • A card is closed or reopened
  • Someone comments
  • A checklist item changes
  • A card is deleted
  • A sprint starts
  • A sprint is completed
Only what automations send
Leave every event off, and the webhook receives only what a rule’s Send to a webhook action sends it.
Send test
Sends a ping, so you can see your endpoint answer before real events arrive.
Deliveries and retries
TaskDeck allows 5 seconds to connect and 10 in all, and doesn’t follow redirects. Timeouts, connection errors, 5xx, 408 and 429 answers are retried after 1, 5 and 30 minutes, with the same body and delivery id.
Safe targets
Endpoints must be HTTPS on a host name. Every delivery checks that the address is public and connects only to the address it checked.
Status
Each webhook shows when it last delivered and its last failure, if any.

What a delivery looks like

A card_moved delivery. Card events carry the project, the board, the card with its description in Markdown and its development links, who acted and what changed. Comments, checklist items and sprints come with an object of their own.

Headers
X-TaskDeck-Event: card_moved
X-TaskDeck-Delivery: 7f3c9a52-4c1e-4b8e-9d6a-2f0b1c8e5a31
X-TaskDeck-Timestamp: 1791469205
X-TaskDeck-Signature: sha256=8c1f0e…
User-Agent: TaskDeck-Webhooks (+https://taskdeck.me)
Body
{
  "id": "7f3c9a52-4c1e-4b8e-9d6a-2f0b1c8e5a31",
  "event": "card_moved",
  "action": "card.moved",
  "occurred_at": "2026-10-08T14:20:05Z",
  "project": {
    "id": "01a10006-7112-726c-a5cf-93116198893a",
    "name": "Acme"
  },
  "board": {
    "id": "01a0818b-85ef-7146-8010-45bcf740e8ec",
    "title": "Product Roadmap",
    "prefix": "ACM",
    "url": "https://app.taskdeck.me/projects/01a10006-7112-726c-a5cf-93116198893a/boards/01a0818b-85ef-7146-8010-45bcf740e8ec"
  },
  "card": {
    "id": "01a11bc1-aa02-71af-97b3-51a87413a1d0",
    "key": "ACM-24",
    "title": "Fix the Safari date picker",
    "url": "https://app.taskdeck.me/projects/01a10006-7112-726c-a5cf-93116198893a/boards/01a0818b-85ef-7146-8010-45bcf740e8ec#ACM-24",
    "column": {
      "id": "01a0818b-85f3-71b3-9de2-4320a3a87917",
      "title": "In review"
    },
    "closed": false,
    "assignee": {
      "id": 7,
      "name": "Riley Park",
      "agent": false
    },
    "starts_at": "2026-10-06",
    "deadline": "2026-10-09",
    "tags": [
      "bug"
    ],
    "description": "The picker opens behind the dialog in Safari.",
    "links": [],
    "deleted": false
  },
  "actor": {
    "id": 7,
    "name": "Riley Park",
    "agent": false
  },
  "via": null,
  "changes": [
    {
      "field": "column_id",
      "from": "01a0818b-85f3-71b3-9de2-4320a3a87916",
      "to": "01a0818b-85f3-71b3-9de2-4320a3a87917",
      "from_label": "In progress",
      "to_label": "In review"
    }
  ]
}

Verify the signature

Admins can copy the secret at any time, and replace it with New secret.

  1. Rebuild the signed text

    Join the X-TaskDeck-Timestamp header (Unix seconds), a dot and the raw request body, exactly as received.

  2. Sign it with your secret

    Compute an HMAC-SHA256 of that text with the webhook’s secret, which starts with tdwhsec_, and write it as sha256= followed by the hex digest.

  3. Compare safely

    Compare your value with X-TaskDeck-Signature in constant time, and decide how old a timestamp you accept.

  4. Skip repeats

    A retry keeps the body and the X-TaskDeck-Delivery id and is signed again, so remember the ids you have handled.

Node.js
import crypto from 'node:crypto';

// rawBody: the body exactly as it arrived, before parsing.
function isFromTaskDeck(rawBody, headers, secret) {
  const timestamp = headers['x-taskdeck-timestamp'];
  const expected = 'sha256=' + crypto
    .createHmac('sha256', secret)
    .update(`${timestamp}.${rawBody}`)
    .digest('hex');
  const given = String(headers['x-taskdeck-signature'] ?? '');

  return given.length === expected.length
    && crypto.timingSafeEqual(
      Buffer.from(given),
      Buffer.from(expected),
    );
}

Incoming URLs

Each board can have up to 10 incoming URLs. Post JSON to one, and TaskDeck creates a card in the column you chose, or the board’s first column, credited to the URL’s name.

title
Required. The card’s title.
description
Markdown.
starts_at, deadline
Dates written as YYYY-MM-DD.
assignee
The email of someone on the board.
tags, checklist
Up to 20 tags and 50 checklist items.

TaskDeck answers 201 with the new card’s id, key and link, 422 when a field is wrong, and 429 when the URL is sending too fast.

  • The token in the URL is its only key, so keep the URL secret. New URL replaces it and retires the old one.
  • Up to 60 cards a minute and 2,000 a day per URL.
  • Cards created this way don’t set off automations, which run only when a card moves.
Create a card
curl -X POST "https://api.taskdeck.me/v1/hooks/<id>/<token>" \
  -H "Content-Type: application/json" \
  -d '{
    "title": "Customer reports a failed export",
    "description": "Sent from the **support form**.",
    "tags": ["support"],
    "deadline": "2026-10-12"
  }'

Good to know

  • Webhooks are on every plan.
  • Up to 10 outgoing webhooks per project, and 10 incoming URLs per board.
  • Every project member can see the webhooks; only admins see the URLs and secrets and change them.

Webhooks

Questions about webhooks

Is there a delivery log?

No. Each webhook shows when it last delivered and its last failure, and TaskDeck retries a failed delivery three times.

Can an incoming URL update or move cards?

No. Incoming URLs only create cards.

Can a webhook go to a plain http address or an IP?

No. Endpoints must use HTTPS on a public host name.

Give your next project a clear starting point.

Create a board, add your first task, and bring your team together.

No credit card required · Free forever plan