Test Salesforce webhooks
Salesforce sends webhooks as outbound messages: SOAP notifications with selected record fields, triggered by flows, workflow rules, and approval processes. Capture them on a free webhooks.cc endpoint to see exactly what Salesforce sends, then replay deliveries or forward them to your local handler.
No credit card · 50 requests/day free · or get a guest URL without an account
Prefer a walkthrough? Read the local webhook testing guide.
How to test Salesforce webhooks
- 1
Create a webhook endpoint
Sign in free with GitHub, Google, or email to create a persistent endpoint — or grab an instant guest URL at webhooks.cc without an account.
- 2
Point Salesforce at your URL
Paste the endpoint URL into Salesforce: Setup → Outbound Messages → New Outbound Message, then add it to a flow or workflow rule.
- 3
Inspect what arrives
Each delivery appears live in the dashboard with method, headers, body, query parameters, and source IP.
- 4
Forward to localhost or assert in CI
Run whk tunnel <port> to forward webhooks to a local server, or use the TypeScript SDK to wait for and assert on deliveries in tests.
Salesforce webhook authentication
| Algorithm | Mutual TLS |
|---|---|
| Verification in webhooks.cc | Capture deliveries to inspect raw signature material |
Outbound messages are not signed. Check that the SOAP body's OrganizationId is yours, optionally require Salesforce's client certificate and allowlist its IP ranges, and answer with a SOAP notificationsResponse whose Ack is true.
New to signature verification? Read the webhook signature verification guide.
Everything in one place
- Live dashboard — see deliveries the moment they arrive
- Forward to localhost with whk tunnel
- Replay any captured request to any URL
- Mock responses with custom status, headers, and body
- TypeScript SDK assertions for CI
- MCP server for AI coding agents
Salesforce webhook questions
More providers
Your Salesforce webhook URL is seconds away
Sign up free, create an endpoint, and point Salesforce at it.
No credit card · or try without an account