# How to secure my webhook with an APIKEY

**URL:** https://community.make.com/t/how-to-secure-my-webhook-with-an-apikey/4200
**Category:** Questions
**Created:** [September 12, 2022, 6:53am UTC](https://community.make.com/t/how-to-secure-my-webhook-with-an-apikey/4200 "2022-09-12T06:53:13Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![Yaenz](https://avatars.discourse-cdn.com/v4/letter/y/90db22/32.png) [@Yaenz](https://community.make.com/u/Yaenz)
#### Post date: [September 12, 2022, 6:53am UTC](https://community.make.com/t/how-to-secure-my-webhook-with-an-apikey/4200/1 "2022-09-12T06:53:13Z")

</div>

Hello Makers,  
I have a very simple requirement. I’m sure I just missed the solution.  
I want to secure my webhook with an APIKEY. So deposit a key with Make so that only one request with the key in the header comes through.  
As I said, it’s certainly simple, but I don’t see it.  
Thanks for the help

Yaenz

---

<div class="post-metadata">

### Author: ![ecomsilio](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/ecomsilio/32/104_2.png) [@ecomsilio](https://community.make.com/u/ecomsilio)
#### Post date: [September 12, 2022, 7:10am UTC](https://community.make.com/t/how-to-secure-my-webhook-with-an-apikey/4200/2 "2022-09-12T07:10:23Z")

</div>

Hi @Yaenz

1. enable “Get request headers”  

2. Put your token in the header

3. Put a filter between the webhook module and the next module and check if the token matches your token.

Cheers,  
Gijs

---

<div class="post-metadata">

### Author: ![JugaadiTech](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/jugaaditech/32/1254_2.png) [@JugaadiTech](https://community.make.com/u/JugaadiTech)
#### Post date: [September 12, 2022, 7:19am UTC](https://community.make.com/t/how-to-secure-my-webhook-with-an-apikey/4200/3 "2022-09-12T07:19:18Z")

</div>

# 🤣 It Looks like @ecomsilio Beat me to it,

I’m putting my response in a details block to not blow out the thread since the info is pretty similar.

> **Details inside anyways**
>
> # Howdy @Yaenz Welcome to the :make: Make Community!
> 
> ## Heres a much less secure version of what you are looking for, but the basics are here.
> 
> > ### We have a NBA Player projection model as one of our long running services.
> > 
> > it normally runs on a 5-minute update loop, so
> > 
> > ![image](https://europe1.discourse-cdn.com/flex013/uploads/make/original/2X/6/6c601ef85914ca8a8c3fdbef161b20aad2eff332.png)  
> > (It passes a true value) note this)
> 
> * * *
> 
> > ### But sometimes the subject experts in the NBA department need to push a manual update, or correct an automatic one.
> > 
> > ![image](https://europe1.discourse-cdn.com/flex013/uploads/make/original/2X/d/d1995d55b6f9b0c98b98763fa46402b012467a98.png)
> 
> > ### I needed a way to tell if a push was manual or automatic. if the automatic =TRUE, then it sends an “x” discord message, if not it goes the other route.
> > 
> > ![image](https://europe1.discourse-cdn.com/flex013/uploads/make/original/2X/b/bd10d10d7ee65eaf0cca0f0e666c9acb46f6b38b.png)
> 
> > ### ℹ You can add a query string to a button by doing `hook.eu1.make.com/xxxxxxxxxxxxxxxxxx?yourkey=xxxxxxxxxxxxxx,`
> > 
> > ⚠ That’s **generally not recommended** Heres a very simple version of what you are going for! for secret keys that protect highly sensitive data. those are better to put in the body.
> 
> Let me know if this is enough to get you going 😃   
> **Happy to elaborate more if needed.**

---

<div class="post-metadata">

### Author: ![Yaenz](https://avatars.discourse-cdn.com/v4/letter/y/90db22/32.png) [@Yaenz](https://community.make.com/u/Yaenz)
#### Post date: [September 12, 2022, 7:21am UTC](https://community.make.com/t/how-to-secure-my-webhook-with-an-apikey/4200/4 "2022-09-12T07:21:15Z")

</div>

Thanks to @ecomsilio that sound so good.  
How this should look like? Would be great if you could show me an example please

---

<div class="post-metadata">

### Author: ![ecomsilio](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/ecomsilio/32/104_2.png) [@ecomsilio](https://community.make.com/u/ecomsilio)
#### Post date: [September 12, 2022, 8:05am UTC](https://community.make.com/t/how-to-secure-my-webhook-with-an-apikey/4200/5 "2022-09-12T08:05:38Z")

</div>

Here you go 🙂

[https://dl.dropboxusercontent.com/s/5knf14ld6fmwmpx/Bildschirmaufnahme%202022-09-12%20um%2010.02.35.mov?dl=0](https://dl.dropboxusercontent.com/s/5knf14ld6fmwmpx/Bildschirmaufnahme%202022-09-12%20um%2010.02.35.mov?dl=0)

---

<div class="post-metadata">

### Author: ![R-SimplifiedWebhooks](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/r-simplifiedwebhooks/32/3914_2.png) [@R-SimplifiedWebhooks](https://community.make.com/u/R-SimplifiedWebhooks)
#### Post date: [September 12, 2022, 8:31am UTC](https://community.make.com/t/how-to-secure-my-webhook-with-an-apikey/4200/6 "2022-09-12T08:31:51Z")

</div>

If I had multiple API-Keys - lets say for customers -, I’d simply check the list of keys and filter on the condition it exists?  
Nice!

---

<div class="post-metadata">

### Author: ![Yaenz](https://avatars.discourse-cdn.com/v4/letter/y/90db22/32.png) [@Yaenz](https://community.make.com/u/Yaenz)
#### Post date: [September 12, 2022, 9:00am UTC](https://community.make.com/t/how-to-secure-my-webhook-with-an-apikey/4200/7 "2022-09-12T09:00:48Z")

</div>

Thanks so much … thats it.

---

<div class="post-metadata">

### Author: ![Make\_Bot](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/make_bot/32/14661_2.png) [@Make\_Bot](https://community.make.com/u/Make_Bot)
#### Post date: [September 7, 2023, 2:43pm UTC](https://community.make.com/t/how-to-secure-my-webhook-with-an-apikey/4200/8 "2023-09-07T14:43:36Z")

</div>


