HTTPS only
The destination must start with https://. Payloads are JSON. Verify deliveries with the X-Kuga-Signature header and the signing secret.
POST signed JSON to an HTTPS endpoint the client already trusts. Webhooks live on the client, next to conversations and Contact Requests. Available on Pro and Advanced.
{
"event_type": "contact_request.created",
"timestamp": "2026-08-31T12:00:00.000Z",
"name": "Alex",
"contact": "alex@example.com",
"message": "Looking for a spring install.",
"attribution": {
"utm_source": "google",
"utm_medium": "cpc",
"utm_campaign": "spring",
"landing_page": "https://client.com/?utm_source=google",
"referrer": "https://www.google.com/"
}
}Subscribe to what the destination should receive.
contact_request.createdWebsite Chat or an AI Form captures a lead.
conversation.endedA visitor conversation on this client ends.
funnel.submittedA public AI Form response is accepted.
handover.requestedA customer is waiting for an operator.
handover.acceptedAn operator has taken over.
handover.timed_outThe conversation moved to contact fallback.
It is a switch on Website Chat, off until the agency turns it on, and it is included on every plan. When it is on, contact requests, ended conversations, and AI Form submissions can include source, medium, campaign, term, content, click IDs, landing page, and referrer. The same fields stay on the conversation and in exports when no webhook is connected. Handover events leave them out. If the visitor denies analytics cookies, the UTM fields are omitted.
The destination must start with https://. Payloads are JSON. Verify deliveries with the X-Kuga-Signature header and the signing secret.
Subscribe to contact requests, ended conversations, AI Form submissions, and human handover requested, accepted, or missed.
Kuga does not replace HubSpot or Salesforce. A webhook is how those systems stay involved.
Same client workspace.
Keep the infrastructure.