# Start an automation from another app

> Use the Webhook Received trigger to get a private link. When Zapier, Make or your own site sends data to it, the automation runs with that data.
>
> Source: https://docs.bcl.my/automation-webhook-received/

Most automations start from something in BCL, such as a payment. The **Webhook Received** trigger starts an automation from outside BCL. BCL gives the automation a private link. When another app, such as Zapier, Make or your own website, sends data to that link, the automation runs with that data.

## Start from a template

Two templates use this trigger, under **Automations** → **Templates**:

- **Email Me From Another App** emails you the details each time data arrives.
- **Add Contacts From Other Apps** adds each person to your Bukku contacts (see [Record your sales in Bukku](/bukku/)).

*(Screenshot: The Email Me From Another App template card with Use template highlighted)*

## Set up the trigger

To use the trigger in your own automation:

1. Create an automation (see [Create an automation](/create-automation/)) and pick **Webhook Received** under **Webhooks** as the trigger.
2. Double-click the trigger to open **Webhook Received Trigger Settings**, and copy the **Webhook link**.
3. Paste the link in the other app as the address to send to. Send a POST request with a JSON body or form fields.
4. Send one test request from the other app. The fields it sent show in **Variables** under **From the webhook**, so later steps can use them. While the automation is off, BCL keeps the request as a sample but does not run the steps.
5. Add your steps, for example a **Send Email** step, and use the webhook variables in them.
6. Click **Update Automation** and switch the automation on.

BCL accepts up to 60 requests a minute for each automation, and up to 64 KB for each request.

## Accept signed requests only

Anyone who has the link can start the automation. To accept requests from your own apps only:

1. In **Webhook Received Trigger Settings**, turn on **Require a signature**.
2. Copy the **Signing secret**.
3. In the other app, add the header `X-BCL-Signature` to each request. Its value is `sha256=` followed by the HMAC-SHA256 of the raw request body, made with the signing secret.
4. Click **Save**.

BCL then refuses each request without a valid signature.

> **Caution**
> If the link or the secret leaks, make a new link in the trigger settings. The current link stops working at once, so update it in every app that sends to it.

## Common issues

### What can another app send to the webhook link?

A POST request with a JSON body or form fields, up to 64 KB. Each field becomes a variable, and nested JSON fields become names like customer_email.

### Can anyone start my automation with the link?

Anyone who has the link can. To accept only your own apps, turn on Require a signature and sign each request with the Signing secret.

### I think my webhook link leaked. What do I do?

Make a new link in the trigger settings. The old link stops working at once, so paste the new link into every app that sends to it.
