Webhooks

Multilistado notifies your CRM or website as soon as a lead arrives or a listing changes status, with a signed JSON POST.

Leer en español · Markdown · Updated

Set up

  1. Go to Portal → More → Webhooks.
  2. Enter your receiver URL: it must be https:// on a public server (private IPs and localhost are refused).
  3. Tick the Events you want and click Create.
  4. Copy the secret shown ("Webhook created. Secret (save it): …"): it is shown only once and is used to verify the signature.
  5. Click Test to send a test lead.created. The Last status column shows ok, http 4xx/http 5xx or error: delivery failed with the time.

Webhooks are per agent: you receive events for your listings and for leads assigned to you.

Free for licensed agents and agencies. Create your account, verify your license and generate your API key or widget in minutes.

Create a free account I already have an account

Events

EventWhen it is sentdata
lead.createdWhen a new lead is notified to you: forms on multilistado.mx, your Multilistado site, the widget and collections. Showing requests are sent once the buyer finishes verifying their IDid, name, email, phone, message, kind (info/tour), id_status, listing {id, slug, title}, source
lead.updatedWhen you change a lead's stage in the portalid, status
listing.publishedWhen a listing is published (portal or API) or reconfirmedid, slug, title, status
listing.unpublishedWhen it is unpublished, withdrawn, marked sold/rented or hidden by the system (e.g. not reconfirmed)id, slug, status (sometimes title)
listing.updatedThe agent edited a published listing in the portal (not sent for edits made via the API)id, slug, title, status

No webhooks are sent for leads you create with POST /leads or for your API PUTs (this avoids loops with CRMs that sync both ways).

Payload

POST /hooks/multilistado HTTP/1.1
Content-Type: application/json
X-PBM-Event: lead.created
X-PBM-Signature: sha256=5d41402abc4b2a76b9719d911017c592…

{"event":"lead.created","created_at":"2026-09-30T18:04:11.482Z","data":{"id":"6f1c…","name":"Ana López","email":"ana@example.com","phone":"+52 664 123 4567","message":"Is it still available?","kind":"info","id_status":null,"listing":{"id":"07e2…","slug":"casa-en-venta-playas-de-tijuana","title":"Casa en venta en Playas de Tijuana"},"source":"widget:3f9a0c1e2b4d5a6c7e8f9012"}}

X-PBM-Signature = sha256= + the hex HMAC-SHA256 of the exact body (raw bytes) keyed with your secret. Verify it before parsing the JSON and compare in constant time.

Verify the signature

// Node.js 18+, no dependencies. MULTILISTADO_WEBHOOK_SECRET = the secret from the portal.
import http from 'node:http';
import crypto from 'node:crypto';

const SECRET = process.env.MULTILISTADO_WEBHOOK_SECRET;

function validSignature(rawBody, header) {
  const expected = 'sha256=' + crypto.createHmac('sha256', SECRET).update(rawBody).digest('hex');
  const a = Buffer.from(String(header || '')), b = Buffer.from(expected);
  return a.length === b.length && crypto.timingSafeEqual(a, b);
}

http.createServer((req, res) => {
  const chunks = [];
  req.on('data', c => chunks.push(c));
  req.on('end', () => {
    const raw = Buffer.concat(chunks);                       // raw bytes: do not use JSON.stringify(req.body)
    if (!validSignature(raw, req.headers['x-pbm-signature'])) { res.writeHead(401).end('bad signature'); return; }
    const evt = JSON.parse(raw.toString('utf8'));
    console.log(evt.event, evt.data.id);                     // store it in your CRM (in the background)
    res.writeHead(200).end('ok');                            // answer fast (under 10 s)
  });
}).listen(process.env.PORT || 3000);

Delivery and retries