Open App

Notifications & Webhooks

Find these under Settings → Integrations for each project. Every integration has a Test button that sends a sample testimonial so you can check it end to end.

Settings → Integrations
Slack incoming webhook
Your webhook endpoint
Signing secret

Email#

You get an email for every new testimonial by default. Switch it off with Email me new testimonials in the testimonial form settings.

Slack#

In Slack, create an app, turn on Incoming Webhooks, add one for the channel you want, and paste its URL (https://hooks.slack.com/services/…). Each new testimonial is posted with its rating, quote, author and a Review button.

Discord#

In the channel's settings open Integrations → Webhooks → New webhook, copy its URL (https://discord.com/api/webhooks/…) and paste it in.

Webhooks (Zapier, Make, n8n, your API)#

Paste any https:// URL and ShowTrust sends a POST with JSON on two events: testimonial.created (someone submitted on your testimonial page) and testimonial.approved (you approved one). In Zapier use Webhooks by Zapier → Catch Hook; in Make use a Custom webhook. Failed deliveries are retried once.

json
{
  "event": "testimonial.created",
  "createdAt": "2026-09-30T12:00:00.000Z",
  "data": {
    "id": "…",
    "projectId": "…",
    "status": "pending",
    "kind": "text",
    "authorName": "Jane Doe",
    "authorRole": "CEO",
    "authorCompany": "Acme",
    "authorAvatar": null,
    "text": "…",
    "rating": 5,
    "videoUrl": null,
    "source": "public_page",
    "importPlatform": null,
    "tags": [],
    "submittedAt": "2026-09-30T12:00:00.000Z",
    "wallUrl": "https://showtrust.to/w/acme"
  }
}

Customer email addresses are never included.

Verifying signatures#

Each request carries X-ShowTrust-Event, X-ShowTrust-Timestamp and X-ShowTrust-Signature: sha256=… — an HMAC-SHA256 of timestamp + "." + raw body using your signing secret (shown in the dashboard; you can rotate it). Reject requests older than five minutes.

verify.jstsx
const crypto = require('crypto');

function isValidShowTrustWebhook(headers, rawBody, secret) {
  const ts = headers['x-showtrust-timestamp'];
  const sig = headers['x-showtrust-signature'] || '';
  const expected =
    'sha256=' + crypto.createHmac('sha256', secret).update(ts + '.' + rawBody).digest('hex');
  const fresh = Math.abs(Date.now() / 1000 - Number(ts)) < 300;
  return (
    fresh &&
    sig.length === expected.length &&
    crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(expected))
  );
}

Send invites from your app#

The other direction: trigger a testimonial request from your own code (after a purchase, at the end of onboarding) with POST /v1/projects/:id/invites. Customers who unsubscribed, already responded or were asked in the last week are skipped, so it's safe to call on every event.

Was this page helpful?

ShowTrust

Collect testimonials. Show off the trust.

© Copyright 2026. All rights reserved.