LinkedIn webhooks: events as they happen
Swarmhit's LinkedIn webhooks push events to your endpoint as they happen: a lead replies, accepts an invitation, gets imported, or an account needs attention. Register an endpoint with POST /webhooks, store the secret, and verify the HMAC-SHA256 signature on every delivery. Failed deliveries are retried with exponential backoff and recent attempts are logged, so your product never polls LinkedIn state.
Endpoints
POST/webhooks
Register an endpoint
GET/webhooks/deliveries
Read the delivery log
POST/webhooks/{id}/test
Send a test event
/webhooks
api/v1// Verify a Swarmhit webhook (Node.js)
const crypto = require("crypto");
const signature = Buffer.from(req.headers["x-swarmhit-signature"] || "");
const expected = Buffer.from(
crypto.createHmac("sha256", SIGNING_SECRET).update(rawRequestBody).digest("hex")
);
// timingSafeEqual throws when byte lengths differ, so compare them first
const ok =
signature.length === expected.length && crypto.timingSafeEqual(expected, signature);How LinkedIn webhooks work
- Each delivery carries X-Swarmhit-Event (the event type), X-Swarmhit-Delivery (a unique id, use it to deduplicate since delivery is at least once) and X-Swarmhit-Signature, an HMAC-SHA256 digest of the raw body keyed by the endpoint's secret.
- Answer with any 2xx to acknowledge. Other answers are retried with exponential backoff, and an endpoint that keeps failing is disabled automatically. GET /webhooks/deliveries and /webhooks/{id}/deliveries show recent attempts (kept 7 days), and a failed one can be resent once the endpoint is enabled.
- LinkedIn events include message.received, message.sent, connection.accepted, lead.status_changed, lead.imported, comment.pending, voice_note.pending, campaign.finished, account.connected, account.connection_failed, account.status_changed, account.paused and account.resumed. Email events (sent, received, bounced, opened, clicked, unsubscribed) cover the cold email channel, in beta.
Inside campaigns
One POST /campaigns sets up a whole sequence, and the engine schedules each step per sender and mailbox, inside the sending window, with rotation across senders.
- Webhooks are how a campaign reports back: accepted invites, replies and finished campaigns arrive as events, which is how an AI agent or a CRM workflow knows when to act without polling.
Limits and safety
- Delivery is at least once: deduplicate on X-Swarmhit-Delivery.
- An endpoint that keeps failing is disabled automatically; fix it, enable it again and resend the failed deliveries from the log within 7 days.
LinkedIn senders cost $16.90 a month each for the first 50, tiered down to $6.90, with no minimum. See pricing.
Webhooks
Events to subscribe to: message.received, connection.accepted, account.status_changed. Deliveries are signed and retried.
LinkedIn webhooks, answered
Does LinkedIn offer webhooks for messages and invitations?
Not for outreach on member accounts. Swarmhit emits its own webhooks for the senders you connect: replies, accepted invitations, imports, AI drafts waiting for approval and account status changes, each signed so you can trust the payload.
How do I verify a Swarmhit webhook?
Compute an HMAC-SHA256 of the raw request body with the endpoint's signing secret and compare it, in constant time, with the X-Swarmhit-Signature header. The secret comes back when you create the endpoint; store it with your other credentials.
What happens if my endpoint is down?
Non-2xx answers are retried with exponential backoff. If the endpoint keeps failing it is disabled automatically; the delivery log keeps recent attempts for 7 days, so you can enable the endpoint again and resend what was missed.
More LinkedIn API endpoints
LinkedIn inbox API
Read and reply
ReadLinkedIn connection request API
Send a connection request
ReadLinkedIn search API
Import a LinkedIn search
ReadLinkedIn comment API
Comment on a post
Read- Sequencer built in
- 250+ safeguards monitored 24/7
- REST API and signed webhooks