# Webhook password how-to

**URL:** <https://community.glideapps.com/t/webhook-password-how-to/60740>\
**Category:** Ask for Help\
**Created:** [April 19, 2023, 8:45pm UTC](https://community.glideapps.com/t/webhook-password-how-to/60740 "2023-04-19T20:45:35Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![pvutrix](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/pvutrix/32/55588_2.png) [@pvutrix](https://community.glideapps.com/u/pvutrix)\
**Post date:** [April 19, 2023, 8:45pm UTC](https://community.glideapps.com/t/webhook-password-how-to/60740/1 "2023-04-19T20:45:35Z")

</div>

Hello everyone,

It’s not clear how to authenticate the webhook, what type should be used. I’m frustrated that I can authenticate with Postman in 3 different ways, yet not with Glide.

Is it API key authentication or Bearer token or Basic? Or what?

 ![image](https://us1.discourse-cdn.com/flex002/uploads/glideapps/original/3X/c/c/ccdd0e913f902d4be9464c4c4bedf8d9dff9ba24.png)

 ![image](https://us1.discourse-cdn.com/flex002/uploads/glideapps/original/3X/6/2/62951f4466fff5241eec003b74718aa36dd401e9.png)

 ![image](https://us1.discourse-cdn.com/flex002/uploads/glideapps/original/3X/a/9/a9c3d25e451618c4e67ecd576cc4f1574aa1539b.png)

Please update the docs and provide a sample call for Postman.

Best regards,  
Paul

---

<div class="post-metadata">

**Author:** ![Jeff\_Hager](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jeff_hager/32/43_2.png) [@Jeff\_Hager](https://community.glideapps.com/u/Jeff_Hager)\
**Post date:** [April 19, 2023, 10:38pm UTC](https://community.glideapps.com/t/webhook-password-how-to/60740/2 "2023-04-19T22:38:23Z")

</div>

The password is sent in the headers of the webhook. You would authenticate on the other end. For example, you could set up Make to only do something if the password that’s sent with the webhook matches what Make is set up to look for. That way, people could attempt to call your webhook, but would only be successful if they know the password.

An additional note, is not a good idea to share that password in a public forum.

---

<div class="post-metadata">

**Author:** ![pvutrix](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/pvutrix/32/55588_2.png) [@pvutrix](https://community.glideapps.com/u/pvutrix)\
**Post date:** [April 24, 2023, 5:50pm UTC](https://community.glideapps.com/t/webhook-password-how-to/60740/3 "2023-04-24T17:50:01Z")

</div>

Thx Jeff, but my question was not why the password is needed, but about what specific values are passed within the header.

Through testing I’ve found this out myself.

Glide passes the following header, which one could use to authorize webhooks.  
Header name : Authorization  
Header value : Basic $password

$password being the variable shown when the webhook is created

---

<div class="post-metadata">

**Author:** ![fluidwebapp](https://avatars.discourse-cdn.com/v4/letter/f/49beb7/32.png) [@fluidwebapp](https://community.glideapps.com/u/fluidwebapp)\
**Post date:** [May 31, 2023, 7:01pm UTC](https://community.glideapps.com/t/webhook-password-how-to/60740/4 "2023-05-31T19:01:45Z")

</div>

Thank you for explaining, really brings me forward.

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [June 28, 2023, 8:13am UTC](https://community.glideapps.com/t/webhook-password-how-to/60740/5 "2023-06-28T08:13:27Z")

</div>

> [@pvutrix](#):
>
> Through testing I’ve found this out myself.
> 
> Glide passes the following header, which one could use to authorize webhooks.  
> Header name : Authorization  
> Header value : Basic $password
> 
> $password being the variable shown when the webhook is created

The [docs](https://www.glideapps.com/docs/reference/actions/webhook#authentication) have been updated to include this information.

 ![CleanShot 2023-06-28 at 16.12.41@2x](https://us1.discourse-cdn.com/flex002/uploads/glideapps/original/3X/3/4/341423fa9db22f717c44bc98f59a53cd696f9204.png)

---

<div class="post-metadata">

**Author:** ![Gregory](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/gregory/32/21180_2.png) [@Gregory](https://community.glideapps.com/u/Gregory)\
**Post date:** [April 25, 2024, 9:51am UTC](https://community.glideapps.com/t/webhook-password-how-to/60740/6 "2024-04-25T09:51:54Z")

</div>

Dear @Darren_Murphy ,

where can I find the password in the new webhook config?  
Mine looks like this:

 ![webhook_no pw](https://us1.discourse-cdn.com/flex002/uploads/glideapps/original/3X/c/b/cb0ddecc54c3906646d1a08ca88025f8c7cd3525.png)

Whereas the old webhook config looks like this:

 ![old webhook_with pw](https://us1.discourse-cdn.com/flex002/uploads/glideapps/original/3X/7/1/71c6ae8e1b1bd820dd135a3de638fec10f8969a9.png)

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![Kenny\_Gordon](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kenny_gordon/32/76485_2.png) [@Kenny\_Gordon](https://community.glideapps.com/u/Kenny_Gordon)\
**Post date:** [June 13, 2024, 1:07am UTC](https://community.glideapps.com/t/webhook-password-how-to/60740/7 "2024-06-13T01:07:21Z")

</div>

Yeah, this is an unfortunate regression - I’m having difficulty understanding why authentication would be removed from webhooks. It would be very useful to have again.
