Webhook
An automatic message one system sends another the moment something changes.
Quick Answer
A webhook is an HTTP message that a software platform sends to a URL you specify whenever a defined event occurs, such as a new drawing upload or a changed RFI status. Instead of repeatedly asking an API whether anything changed, the receiving system is notified instantly, which keeps connected construction tools in sync.
The Full Picture
Most construction software exposes an API, which lets another program ask for data on request. The weakness of that pull model is timing: to learn that a submittal changed status, your integration has to keep asking, over and over, and most of those requests return nothing new. Webhooks reverse the direction. You register a URL, tell the platform which events you care about, and the platform calls that URL when one of them happens.
Mechanically, the sending platform posts a small payload, usually JSON, describing what happened: the type of event, the affected record, and often an identifier you then use to fetch full details through the regular API. Your receiving endpoint should respond quickly with a success code, then do the real work asynchronously. If it fails to respond, many platforms retry on a schedule, so receivers need to handle the same event arriving more than once.
Security matters because a webhook endpoint is a public door into your systems. Common safeguards include a shared secret used to sign each payload with a keyed hash such as HMAC, so the receiver can verify the message really came from the platform, along with HTTPS, narrow event subscriptions, and logging. Treat the payload as a notification to verify, not as trusted truth.
In construction, webhooks typically connect a project management or document platform to everything around it: notifying a chat channel when a drawing set is revised, kicking off a data sync when an RFI closes, or triggering a review workflow when new files land in a folder. They are plumbing, not a product, and the value depends on what is built on top of them.
Real Examples
Common Misconceptions
People assume: A webhook is just another name for an API.
Actually: An API is an interface you call to request or change data. A webhook is the reverse: the platform calls you when something happens. Most integrations use both, with the webhook as the trigger and the API as the way to fetch details.
People assume: A webhook payload contains everything you need and can be trusted as is.
Actually: Payloads are often thin notifications, and anyone can send a request to a public URL. Verify the signature, and fetch the authoritative record through the API before acting on it.
Frequently Asked Questions
What is a webhook in simple terms?
It is an automatic notification. When a chosen event happens in one system, that system sends an HTTP request to a web address you provided, telling your system about it right away.
What is the difference between a webhook and polling?
Polling means your system asks the API on a schedule whether anything changed. A webhook means the source system tells you when something changes. Webhooks are usually faster and waste fewer requests.
Are webhooks secure?
They can be, if you use HTTPS, verify a signature or shared secret on every request, limit the events you subscribe to, and treat payloads as untrusted until confirmed against the API.
Does Procore support webhooks?
Yes. Procore documents webhooks for subscribing to events on supported resources through its developer platform. Available event types change over time, so check the current documentation.
What happens if my webhook receiver is down?
Behavior varies by platform. Many retry for a limited time and then give up, so design receivers to respond fast, process asynchronously, and reconcile missed events through the API.