Before you start
- You need an HTTPS endpoint that accepts
POSTrequests withContent-Type: application/json. For Power Automate, create a flow with the When a HTTP request is received trigger. - The URL must be
https://and point to a public host. MSPortal rejects localhost, private IP ranges (10.x, 192.168.x, 172.16-31.x), link-local, and carrier-grade NAT addresses. - The receiving workflow can act as soon as it gets a request, so use a test flow first.
Set up a webhook
Open the template
Expand Flow Webhook (JSON)
Turn on delivery
Choose a Delivery mode
- Create PSA ticket + webhook creates the ticket as usual and also sends the JSON.
- Webhook only sends the JSON and skips PSA ticket creation.
Paste the Webhook URL
Add a shared secret (optional)
X-MSPortal-Signature header your flow can verify. Leave it blank to skip signing. Do not put secrets in the URL.Send a test event
ticket.test request using your template’s field keys with sample values. A message such as “Test sent (HTTP 200). Check your Flow run history.” confirms delivery. The test does not save the template, and your receiving flow can still take real actions.Save the template
Test with a request inspector first
A free request inspector such as webhook.site shows exactly what MSPortal sends before you build any flow logic.Get a unique URL
Paste it into MSPortal
Send a test event
Inspect the payload
Connect Power Automate
Create the flow
Save once to generate the URL
Copy the HTTP POST URL
Paste it into MSPortal and test
Generate the schema
fields.username, ticket.number, and the other properties as dynamic content.Build the rest of the flow
Make a webhook-only template
Use this for requests that live entirely outside the PSA.Set the delivery mode
Clear old PSA defaults (optional)
Enter the URL and save
What happens on each submission
The JSON payload
Top-level shape
Top-level shape
"event": "ticket.submitted" and your tenant ID. Test events use "event": "ticket.test" and the literal tenant ID "test-tenant".The fields object
The fields object
fields uses your template’s own field keys. A template with fields username, asset_tag, and reason sends:null. Multi-select answers arrive as arrays, numbers as numbers, and checkboxes as booleans.When PSA fields are null
When PSA fields are null
ticket.id, ticket.number, ticket.external_url, ticket.board, ticket.status, and ticket.priority are null. summary, description, and fields are always filled. Branch on ticket.number in your flow to handle both cases.Headers
Headers
Verify the signature
When a shared secret is set, computeHMAC-SHA256(secret, raw request body) as lowercase hex, add the sha256= prefix, and compare it to X-MSPortal-Signature. Use the raw body bytes before you parse or re-serialize the JSON.
A valid signature shows the sender knew the secret. It does not stop a request from being replayed, so make your receiver safe to run twice for any step that must not repeat.
Check recent deliveries
Open the saved template and expand Flow Webhook (JSON). Recent deliveries lists each attempt with its time, HTTP status, duration, and any error. Test attempts carry a Test badge. MSPortal sees only the HTTP result, so also check your receiving flow’s run history.Embedded templates
If a template contains an embedded template, each template’s own webhook fires on its own. The parent’s webhook fires for the parent submission, and each embedded template’s webhook fires for that embed’s ticket. Test the nesting you plan to use. To stop an embed from firing a webhook, leave it unconfigured on the embedded template.Troubleshooting
Frequently asked questions
Does Send test event save my settings?
Does Send test event save my settings?
Can the test event trigger real actions?
Can the test event trigger real actions?
ticket.test and handle it safely. Use a controlled test path.How do I stop a template from creating PSA tickets?
How do I stop a template from creating PSA tickets?
Does HTTP 200 prove my provisioning flow finished?
Does HTTP 200 prove my provisioning flow finished?
Should I resubmit after a timeout?
Should I resubmit after a timeout?
Do branches use the parent's webhook?
Do branches use the parent's webhook?