Skip to main content
A ticket template can send a JSON copy of every submission to a webhook URL you control. Use it to start a Power Automate, Logic Apps, n8n, or Zapier workflow, or as the only destination for requests that should never create a PSA ticket, such as HR change requests or approvals. This guide is for MSP staff whose role can write or manage ticket settings.

Before you start

  • You need an HTTPS endpoint that accepts POST requests with Content-Type: application/json. For Power Automate, create a flow with the When a HTTP request is received trigger.
  • The URL must be https:// and point to a public host. MSPortal rejects localhost, private IP ranges (10.x, 192.168.x, 172.16-31.x), link-local, and carrier-grade NAT addresses.
  • The receiving workflow can act as soon as it gets a request, so use a test flow first.

Set up a webhook

1

Open the template

Go to Settings > Tickets > Templates and open the template.
2

Expand Flow Webhook (JSON)

Scroll past PSA Integration Settings and click Flow Webhook (JSON) to expand it.
3

Turn on delivery

Check Send submissions to a Flow webhook.
4

Choose a Delivery mode

  • Create PSA ticket + webhook creates the ticket as usual and also sends the JSON.
  • Webhook only sends the JSON and skips PSA ticket creation.
Choosing Webhook only also clears any TimeZest appointment scheduling on the template, because no ticket exists to schedule against.
5

Paste the Webhook URL

Paste your endpoint into Webhook URL (https only). In Power Automate, copy it from the When a HTTP request is received trigger.
6

Add a shared secret (optional)

Enter a random string in Shared secret (optional). Every request then carries an X-MSPortal-Signature header your flow can verify. Leave it blank to skip signing. Do not put secrets in the URL.
7

Send a test event

Click Send test event. MSPortal posts a ticket.test request using your template’s field keys with sample values. A message such as “Test sent (HTTP 200). Check your Flow run history.” confirms delivery. The test does not save the template, and your receiving flow can still take real actions.
8

Save the template

Click Save Template. Real submissions use the saved configuration, not the unsaved editor values.

Test with a request inspector first

A free request inspector such as webhook.site shows exactly what MSPortal sends before you build any flow logic.
1

Get a unique URL

Open webhook.site. It creates a unique URL for you. Copy it.
2

Paste it into MSPortal

In Flow Webhook (JSON), paste the URL into Webhook URL (https only) and check Send submissions to a Flow webhook.
3

Send a test event

Click Send test event. The request appears in the inspector within a couple of seconds.
4

Inspect the payload

Click the request to see the headers and JSON body. This is the shape your flow receives. Copy the body for the next section.
Save the template and submit a real request with the inspector URL still in place to see a production payload, including the PSA ticket number. Then swap in your real flow URL. Do not send sensitive production data to a public inspection service.

Connect Power Automate

1

Create the flow

In Power Automate, create an instant or automated cloud flow and choose the When a HTTP request is received trigger.
2

Save once to generate the URL

Power Automate only issues the URL after the flow is saved with the trigger in place. Add a placeholder action, such as a Compose with a static value, and click Save.
3

Copy the HTTP POST URL

Reopen the trigger and copy HTTP POST URL.
4

Paste it into MSPortal and test

Paste the URL into Webhook URL (https only), check Send submissions to a Flow webhook, and click Send test event.
5

Generate the schema

In the trigger, click Use sample payload to generate schema and paste the JSON body you captured. Power Automate then offers fields.username, ticket.number, and the other properties as dynamic content.
6

Build the rest of the flow

Add the actions you want, such as a SharePoint list item, a Teams message, or a database write.
The Power Automate trigger URL is itself a secret. If the flow provisions, deletes, or changes credentials, set a shared secret in MSPortal and verify X-MSPortal-Signature in the first step of the flow.

Make a webhook-only template

Use this for requests that live entirely outside the PSA.
1

Set the delivery mode

In Flow Webhook (JSON), check Send submissions to a Flow webhook and choose Webhook only. The PSA Integration Settings section is then disabled for the template.
2

Clear old PSA defaults (optional)

If the template still holds a board, priority, or status, open PSA Integration Settings and click Clear PSA defaults so no stale routing remains.
3

Enter the URL and save

Add the Webhook URL (https only), then click Save Template. The Flow Webhook (JSON) header shows a Webhook only badge.
Webhook-only templates still follow company visibility, role access, and required-field rules. A successful submission shows “Submission was sent to your configured Flow webhook. No PSA ticket was created.” If the webhook fails, the requester sees “Flow webhook delivery failed”, and there is no email fallback in this mode.

What happens on each submission

The webhook waits up to 10 seconds for a response. Do not submit the same real request again just because a webhook timed out. Check the PSA and your receiving flow first, because either may already have acted.

The JSON payload

Real submissions use "event": "ticket.submitted" and your tenant ID. Test events use "event": "ticket.test" and the literal tenant ID "test-tenant".
fields uses your template’s own field keys. A template with fields username, asset_tag, and reason sends:
Every field key in the template is present. Unanswered optional fields are null. Multi-select answers arrive as arrays, numbers as numbers, and checkboxes as booleans.
On webhook-only submissions, or when PSA creation failed, ticket.id, ticket.number, ticket.external_url, ticket.board, ticket.status, and ticket.priority are null. summary, description, and fields are always filled. Branch on ticket.number in your flow to handle both cases.

Verify the signature

When a shared secret is set, compute HMAC-SHA256(secret, raw request body) as lowercase hex, add the sha256= prefix, and compare it to X-MSPortal-Signature. Use the raw body bytes before you parse or re-serialize the JSON. A valid signature shows the sender knew the secret. It does not stop a request from being replayed, so make your receiver safe to run twice for any step that must not repeat.

Check recent deliveries

Open the saved template and expand Flow Webhook (JSON). Recent deliveries lists each attempt with its time, HTTP status, duration, and any error. Test attempts carry a Test badge. MSPortal sees only the HTTP result, so also check your receiving flow’s run history.

Embedded templates

If a template contains an embedded template, each template’s own webhook fires on its own. The parent’s webhook fires for the parent submission, and each embedded template’s webhook fires for that embed’s ticket. Test the nesting you plan to use. To stop an embed from firing a webhook, leave it unconfigured on the embedded template.

Troubleshooting

Frequently asked questions

No. It sends a real request using the current editor values. Click Save Template before you expect real submissions to use them.
Yes. Your flow must recognize ticket.test and handle it safely. Use a controlled test path.
Choose Webhook only and save. Clearing individual PSA fields is not enough on its own.
No. It proves the endpoint accepted the request. Check the later steps and the final record in the receiving system.
Check Recent deliveries, your flow, and the PSA first. A timeout does not prove nothing happened, and resubmitting can duplicate work.
Yes. A company branch without its own webhook setting uses the parent template’s.