Connect Webhooks to Rankauto
Webhooks connect Rankauto to any website or service by sending real-time article data to a URL you choose, every time an article is published or republished. Use this when your platform isn’t one Rankauto connects to natively, when you want to route content through an automation tool, or when you’re building your own publishing pipeline.
Before you begin
Make sure you have:
- A real, publicly reachable URL that can receive an HTTP POST request with a JSON body — a Zapier catch hook, a serverless function, or an API route in your own app all work
Common real use cases:
- A custom-built site or static site generator (Next.js, Hugo, Jekyll)
- A CMS Rankauto doesn’t connect to natively yet
- Automation platforms — Zapier, Make.com, n8n
- Serverless functions — Vercel Functions, AWS Lambda, Cloudflare Workers
- Notification channels — post a Slack or Discord message whenever something publishes
Setting up your webhook
RANKAUTO_WEBHOOK_SECRET) right away.test: true) to your endpoint, so you can confirm it’s reachable and your signature verification works before any real article relies on it.Connecting a webhook replaces any WordPress, Shopify, or Wix connection you have — Rankauto publishes to exactly one place at a time. Reconnecting later, even to the same URL, always generates a brand-new secret.
Authentication
Every webhook request is signed with HMAC-SHA256 over the raw JSON body, using the secret Rankauto generated for you. Rankauto doesn’t support an unsigned mode — every request can be verified. The signature is sent in two headers carrying the identical value, so you can read whichever your framework makes easier:
| Header | Value |
|---|---|
| X-Rankauto-Signature | The raw HMAC-SHA256 hex digest |
| Authorization | sha256=<the same hex digest> |
To verify: compute an HMAC-SHA256 hex digest of the exact raw request body using your stored secret, then compare it to the signature header using a constant-time comparison, not ===. Hashing a re-serialized copy of the body (after your framework has already parsed it into an object) will produce a different digest and always fail — hash the raw bytes you actually received.
Code example
Node.js — signature verification
const crypto = require('crypto');
function verifyRankautoSignature(rawBody, signatureHeader, secret) {
const expected = crypto
.createHmac('sha256', secret)
.update(rawBody)
.digest('hex');
return crypto.timingSafeEqual(
Buffer.from(signatureHeader, 'hex'),
Buffer.from(expected, 'hex')
);
}
app.post('/api/rankauto-webhook', express.raw({ type: 'application/json' }), (req, res) => {
const signature = req.headers['x-rankauto-signature'];
const secret = process.env.RANKAUTO_WEBHOOK_SECRET;
if (!signature || !verifyRankautoSignature(req.body, signature, secret)) {
return res.status(401).json({ message: 'Invalid signature' });
}
const article = JSON.parse(req.body);
if (article.test) {
return res.status(200).json({ message: 'Test received' });
}
// Your real publish logic here.
res.status(200).json({ message: 'Received' });
});Payload structure
Rankauto sends a JSON body shaped like this on every real publish or republish:
{
"title": "How to Build Backlinks for Better SEO",
"content_html": "<h1>How to Build Backlinks...</h1><p>...</p>",
"content_markdown": "# How to Build Backlinks...\n\n...",
"slug": "how-to-build-backlinks-for-better-seo",
"meta_description": "Learn proven strategies to build high-quality backlinks...",
"status": "published",
"featured_image": "https://.../featured.jpg",
"published_url": null,
"published_at": "2026-09-23T15:03:15.416Z",
"is_republish": false,
"test": false
}| Field | Description |
|---|---|
| title | Article title |
| content_html | Full article body, rendered to HTML |
| content_markdown | Full article body, in its original Markdown |
| slug | URL-friendly slug, stays constant across updates to the same article |
| meta_description | SEO meta description, or null if the article has none |
| status | Always "published" — this only fires when an article genuinely goes live |
| featured_image | URL of the featured image, or null |
| published_url | Always null — a webhook target has no page of its own on Rankauto’s side to link to |
| published_at | Real ISO timestamp of this specific delivery |
| is_republish | true when this article was already published before; false on its first publish |
| test | true only for a payload sent via the Send Test button |
Delivery & reliability
Honest, real behavior — read this before relying on webhooks for anything critical:
- A delivery attempt times out after 15 seconds.
- There is no automatic retry. If your endpoint is down, returns an error, or times out, that one delivery is lost — Rankauto logs it (visible on the connection page as “Last delivery: failed …”) but doesn’t queue or retry it. The article is still genuinely published on Rankauto’s own side either way.
- Unpublishing an article never triggers a webhook — only a real publish or republish does.
- Only one webhook URL can be connected per site at a time.
Troubleshooting
My endpoint isn’t receiving anything.
Confirm the URL is genuinely public (not localhost or a private network address) and that you clicked Connect Webhook, not just typed the URL. Also confirm an article was actually published or republished — nothing fires just from generating a draft.
Signature verification always fails.
The most common cause is a stale secret — reconnecting, even to the same URL, always generates a new one. The second most common cause is hashing something other than the exact raw request body.
Send Test succeeds, but real articles never arrive.
A webhook connection alone doesn’t make anything auto-publish. For automated daily generations, turn on Auto Publishing under Settings → Automation. For a manual article, click Publish Now on that article.
Frequently asked questions
Can I use this with Zapier or Make.com?
Yes — point your webhook URL at a Zapier “Catch Hook” or Make.com webhook trigger. Verifying the signature there is optional but recommended if the automation you build does anything sensitive.
Do I need to write code?
Not necessarily. Many automation tools can use the JSON payload directly with no code at all — code is only needed if you want to verify the signature yourself or build custom logic.
Can I have multiple webhook URLs?
No — one active connection per site, same as Rankauto’s other CMS integrations.
Is the data secure?
Every request is signed with HMAC-SHA256 so you can verify it genuinely came from Rankauto and wasn’t tampered with. Your endpoint itself should be a real HTTPS URL — that part is on you, same as any webhook integration.
Other integrations
Set up Rankauto on another platform.
Ready to send Rankauto’s content anywhere?
Connect a webhook from Settings once you’re signed in, or start a free trial to try the whole workflow end to end.
Start 3-day free trial