# Webhooks

> Signed HTTPS callbacks when something happens, with automatic retries.

Section: API, webhooks and security · Canonical: https://intubu.intuitivecapital-dai.com/docs/webhooks

Settings → API & webhooks → Webhooks.

**Subscribing:** give an HTTPS URL and choose the events. Plain HTTP is refused — we will not post your accounting data unencrypted.

**Events include:** invoice created/sent/paid/voided, payment received, bill created/paid, customer and vendor created, bank transaction categorized, reconciliation completed, period closed, journal posted.

**Verifying it is really us:** every delivery carries `X-IntuBu-Signature`, an HMAC-SHA256 of the body using your endpoint's secret. Compute the same HMAC and compare before trusting the payload.

**Retries:** a failed delivery retries with exponential backoff — 1, 2, 4, 8 then 16 minutes — and gives up after six attempts rather than hammering a dead endpoint. Every attempt is logged with its response code.

**Testing:** send a test event from the same screen and watch it arrive in the delivery log.

Deliveries are **outbound only** — IntuBu posts to you. To push data *in*, use the REST API ([API keys](https://intubu.intuitivecapital-dai.com/docs/api-keys)).
