Using Headers in Webhook Block for Secure and Structured API Calls

Headers in Webhook Block


When sending API requests through a Webhook block in your bot flow, headers play a vital role. They carry additional information that helps third-party systems identify, authorize, and understand your request.
Let’s walk through what headers are, why they’re needed, how to use them, and a few examples to make things easier.


Learn more about webhooks: Introduction to Webhook Block in GC 

What are Headers?   

Headers are key-value pairs that are sent along with your webhook request. Think of them as special instructions or identity cards that travel with your request, telling the receiving system who you are and what kind of data you’re sending.

Here’s how a header looks:
  1. Key: Authorization
  2. Value: Bearer your-access-token
Another example:
  1. Key: Content-Type
  2. Value: application/json
These headers are not visible to the end user; they work behind the scenes to make the connection secure, clear, and properly formatted. 



When do you use Headers?   

You’ll typically use headers when:
  1. The API you’re calling requires authentication (e.g., OAuth or API tokens).
  2. You need to set the content type for your request (usually JSON).
  3. You’re working with a service like Zoho, which may need extra details like orgId or portalId.
  4. You want to safely pass sensitive system-level information that should not appear in the request body or URL.
 You can add headers in the “Headers” section of the Webhook block, where you define each key and its corresponding value. 

Why are Headers important?   

Headers are essential for most API calls because they: (Suggestion: Header can be used to mask sensitive information while sending to a third party service. - need to confirm with dev)
  1. Authenticate who is sending the request.
  2. Define what format the request body is in (JSON, XML, etc.).
  3. Pass extra system-level information (like organization or portal IDs).
  4. Ensure that the server understands how to handle your request securely.
Without the right headers, many APIs will reject your request or return an error. 

Commonly Used Headers
Commonly Used Headers
Here are some headers you’ll often use when calling APIs:

Header Key
Example Value
Purpose
Authorization
Bearer ya29.a0AfH6…
Authenticates the request using an access token
Content-Type
application/json
Tells the server the format of the request body
orgId
1234567890
Identifies the Zoho organization making the call
portalId
zylker-support
Used for department-level identification

 You can add up to 20 headers per webhook request, giving you the flexibility to meet any API requirement. 
Example Use Case
Let’s say you want your bot to update a support ticket using the Zoho Desk API. You’ll need to send an authenticated PUT request.

Here’s what your headers might look like:
  1. Authorization: Bearer 1000.abcdeXYZ.your-access-token
  2. orgId: 123456789
  3. Content-Type: application/json
These headers ensure that:
  1. The system knows who you are (Authorization).
  2. It knows you’re part of a specific Zoho organization (orgId).
  3. It understands that your request body is formatted in JSON (Content-Type).
Without these headers, Zoho’s servers would not be able to process your request.

Are Headers secure?   

Yes, headers are invisible to the end users interacting with your bot. This means you can safely include confidential information like:
  1. OAuth tokens
  2. API keys
  3. Internal organization IDs
However, it’s still important to treat this data carefully:
  1. Never expose headers in bot messages.
  2. Store tokens securely and rotate them periodically.
  3. Use HTTPS endpoints to encrypt all communication.
 

Benefits of using Headers   


  1. Securely pass authentication credentials
  2. Ensure your request is formatted correctly
  3. Communicate additional context to external systems
  4. Keep sensitive info hidden from users
  5. Enable access to protected data or APIs


Tips for using Headers   


  1. Always check the API documentation to see which headers are required
  2. Use “Bearer” before your token if the API expects it (e.g., Bearer abc123token)
  3. Don’t include unnecessary headers, only what’s needed
  4. Use test environments first before using headers in live scenarios
  5. Refresh tokens as needed, especially for OAuth-based systems


Learn more about webhooks: Introduction to Webhook Block in GC 

      Create. Review. Publish.

      Write, edit, collaborate on, and publish documents to different content management platforms.

      Get Started Now


        Access your files securely from anywhere

          Zoho CRM Training Programs

          Learn how to use the best tools for sales force automation and better customer engagement from Zoho's implementation specialists.

          Zoho CRM Training
            Redefine the way you work
            with Zoho Workplace

              Zoho DataPrep Personalized Demo

              If you'd like a personalized walk-through of our data preparation tool, please request a demo and we'll be happy to show you how to get the best out of Zoho DataPrep.

              Zoho CRM Training

                Create, share, and deliver

                beautiful slides from anywhere.

                Get Started Now


                  Zoho Sign now offers specialized one-on-one training for both administrators and developers.

                  BOOK A SESSION







                              Quick LinksWorkflow AutomationData Collection
                              Web FormsRetailOnline Data Collection Tool
                              Embeddable FormsBankingBegin Data Collection
                              Interactive FormsWorkplaceData Collection App
                              CRM FormsCustomer ServiceForms for Solopreneurs
                              Digital FormsMarketingForms for Small Business
                              HTML FormsEducationForms for Enterprise
                              Contact FormsE-commerceForms for any business
                              Lead Generation FormsHealthcareForms for Startups
                              Wordpress FormsCustomer onboardingForms for Small Business
                              No Code FormsConstructionRSVP tool for holidays
                              Free FormsTravelFeatures for Order Forms
                              Prefill FormsNon-Profit
                              Forms for Government
                              Intake FormsLegal
                              Mobile App
                              Form DesignerHR
                              Mobile Forms
                              Card FormsFoodOffline Forms
                              Assign FormsPhotographyMobile Forms Features
                              Translate FormsReal EstateKiosk in Mobile Forms
                              Electronic FormsInsurance
                              Drag & drop form builder

                              Notification Emails for FormsAlternativesSecurity & Compliance
                              Holiday FormsGoogle Forms alternative GDPR
                              Form to PDFJotform alternativeHIPAA Forms
                              Email FormsWufoo alternativeEncrypted Forms
                              Accessible FormsTypeform alternativeSecure Forms

                              WCAG

                                          Create. Review. Publish.

                                          Write, edit, collaborate on, and publish documents to different content management platforms.

                                          Get Started Now






                                                            You are currently viewing the help pages of Qntrl’s earlier version. Click here to view our latest version—Qntrl 3.0's help articles.




                                                                Manage your brands on social media

                                                                  Use cases

                                                                  Make the most of Zoho Desk with the use cases.

                                                                   
                                                                    

                                                                  eBooks

                                                                  Download free eBooks and access a range of topics to get deeper insight on successfully using Zoho Desk.

                                                                   
                                                                    

                                                                  Videos

                                                                  Watch comprehensive videos on features and other important topics that will help you master Zoho Desk.

                                                                   
                                                                    

                                                                  Webinar

                                                                  Sign up for our webinars and learn the Zoho Desk basics, from customization to automation and more

                                                                   
                                                                    
                                                                  • Desk Community Learning Series


                                                                  • Meetups


                                                                  • Ask the Experts


                                                                  • Kbase


                                                                  • Resources


                                                                  • Glossary


                                                                  • Desk Marketplace


                                                                  • MVP Corner



                                                                    Zoho Sheet Resources

                                                                     

                                                                        Zoho Forms Resources


                                                                          Secure your business
                                                                          communication with Zoho Mail


                                                                          Mail on the move with
                                                                          Zoho Mail mobile application

                                                                            Stay on top of your schedule
                                                                            at all times


                                                                            Carry your calendar with you
                                                                            Anytime, anywhere




                                                                                  Zoho Sign Resources

                                                                                    Sign, Paperless!

                                                                                    Sign and send business documents on the go!

                                                                                    Get Started Now




                                                                                            Zoho TeamInbox Resources





                                                                                                      Zoho DataPrep Demo

                                                                                                      Get a personalized demo or POC

                                                                                                      REGISTER NOW


                                                                                                        Design. Discuss. Deliver.

                                                                                                        Create visually engaging stories with Zoho Show.

                                                                                                        Get Started Now










                                                                                                                            • Related Articles

                                                                                                                            • Multipath in Webhook Block

                                                                                                                              Not every API call ends the same way. When your chatbot interacts with external systems using a Webhook block, you often expect different types of responses. Some API calls are successful, like when the system finds a customer’s data, while others ...
                                                                                                                            • Request Timeout in Webhook Block

                                                                                                                              When your chatbot connects to an external service, it uses a webhook block to send a request to that service’s API. Now imagine the service takes too long to respond. What should your chatbot do? Wait forever? Give up too early? That’s exactly what ...
                                                                                                                            • URL Field in Webhook Block

                                                                                                                              Where it knows to go! You’ll need to enter the exact REST API endpoint of the third-party app you want to interact with in the URL field; whether you’re sending data, fetching it, updating something, or deleting it. Think of this field as the ...
                                                                                                                            • Connections in Webhook Block

                                                                                                                              When you’re working with webhooks in a bot flow, whether you’re retrieving data, updating a record, or triggering a third-party service, you often need to establish a secure connection with an external application. That’s where Connections come into ...
                                                                                                                            • Response in Webhook Block

                                                                                                                              Once your webhook sends a request to an external API, it often receives a response. This is where the Response List in the webhook block becomes incredibly useful. It lets you capture and use the data that comes back from the API, right inside your ...
                                                                                                                              Wherever you are is as good as
                                                                                                                              your workplace

                                                                                                                                Resources

                                                                                                                                Videos

                                                                                                                                Watch comprehensive videos on features and other important topics that will help you master Zoho CRM.



                                                                                                                                eBooks

                                                                                                                                Download free eBooks and access a range of topics to get deeper insight on successfully using Zoho CRM.



                                                                                                                                Webinars

                                                                                                                                Sign up for our webinars and learn the Zoho CRM basics, from customization to sales force automation and more.



                                                                                                                                CRM Tips

                                                                                                                                Make the most of Zoho CRM with these useful tips.



                                                                                                                                  Zoho Show Resources