← All articles

Webhooks and API authentication

Last updated 10/4/2026

Webhooks and API authentication

Use the Pulseboard API to pull analytics into your own tools, and webhooks to get notified when something happens in your workspace.

Creating an API key

1. Go to Settings → API keys → New key.

2. Give it a name like "ETL pipeline" and choose Read or Read/Write scope.

3. Copy the key — it starts with pb_sk_ and is shown only once.

Authenticate with HTTP Basic Auth using the key as the username and an empty password, or pass Authorization: Bearer pb_sk_....

Rate limits

  • 600 requests per minute per key on Pro, 120 on Starter.
  • Exceeding the limit returns 429 with a Retry-After header.

Webhook events

Register a webhook under Settings → Webhooks. We POST JSON to your URL for these events:

  • dashboard.shared — a dashboard is shared with a new person.
  • source.sync_failed — a data source sync failed 3 times.
  • quota.warning — usage hit 80% of the monthly quota.
  • quota.exceeded — usage hit 100% of the monthly quota.

Verifying webhook signatures

Each POST includes an X-Pulseboard-Signature header: the hex HMAC-SHA256 of the raw body using your webhook secret. Reject any request whose signature doesn't match.

Retries

We retry failed webhook deliveries 5 times with exponential backoff (1, 5, 25, 125, 625 seconds). After the 5th failure the event is dropped and logged under Settings → Webhooks → Delivery log.

Still have questions?

Ask the AI assistant — it answers from these very articles and cites its sources.

Try the chat widget