agentsclimarketplace

Retell webhooks

Skill hookdeck/webhook-skills/skills/retell-webhooks

Webhook integration skills for AI coding agents (Claude Code, Cursor, Copilot). Step-by-step guidance for setting up webhook receivers, signature verification, and event handling for Stripe, Shopify, GitHub, and more. Built on the Agent Skills specification.

Install
npx -y skills add hookdeck/webhook-skills --skill retell-webhooks

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Receive and verify Retell AI webhooks. Use when setting up Retell webhook handlers, debugging X-Retell-Signature verification, or handling voice call events like call_started, call_ended, call_analyzed, and transcript_updated.

The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

7.5 KB, ~1.8k tokens by cl100k_base, as published. Nobody here has run it

Retell AI Webhooks

When to Use This Skill

  • How do I receive Retell AI webhooks?
  • How do I verify Retell webhook signatures (X-Retell-Signature)?
  • How do I handle call_ended or call_analyzed events?
  • Why is my Retell webhook signature verification failing?
  • How do I handle transcript, transfer, and chat events from Retell?

Verification (core)

Retell signs each webhook with HMAC-SHA256 using your Retell API key as the secret (only an API key with the webhook badge in the dashboard works). The signature arrives in the X-Retell-Signature header formatted as v={unix_ms_timestamp},d={hex_digest}, where the digest is computed over the raw request body concatenated with the timestamp. Always verify against the raw body, never a re-serialized JSON string.

The Python SDK ships a verify helper (client.verify(body, api_key, signature) — positional params, so the keyword form used in the FastAPI example also works). The Node SDK has no verify helper, so Node handlers verify manually.

Verified against retell-sdk 5.56.0 (PyPI) and 5.46.0 (npm): the Python package exposes retell.lib.webhook_auth.verify, re-exported as client.verify; the npm package has no webhook/verify export. Check your installed version — the helper's presence and argument order have moved between releases.

const crypto = require('crypto');

// Reject signatures older than 5 minutes to prevent replay attacks
const FIVE_MINUTES_MS = 5 * 60 * 1000;

function verifyRetellSignature(rawBody, signatureHeader, apiKey) {
  const match = /^v=(\d+),d=(.*)$/.exec(signatureHeader || '');
  if (!match) return false;
  const [, timestamp, digest] = match;
  if (Math.abs(Date.now() - Number(timestamp)) > FIVE_MINUTES_MS) return false;

  const expected = crypto
    .createHmac('sha256', apiKey)
    .update(rawBody + timestamp) // raw body + timestamp, in that order
    .digest('hex');
  try {
    return crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(digest));
  } catch {
    return false; // length mismatch = invalid
  }
}

Python (FastAPI) uses the official SDK instead:

from retell import Retell

client = Retell(api_key=os.environ["RETELL_API_KEY"])
# client.verify enforces the ~5 min timestamp window and returns a bool
is_valid = client.verify(raw_body.decode("utf-8"),
                         api_key=os.environ["RETELL_API_KEY"],
                         signature=signature_header)

For complete handlers with tests, see examples/express/, examples/nextjs/, examples/fastapi/.

Common Event Types

EventTriggered WhenCommon Use Cases
call_startedA call beginsTrack live calls, update dashboards
call_endedA call finishes (audio done)Persist call record, trigger follow-ups
call_analyzedPost-call analysis completesStore transcript, sentiment, summary
transcript_updatedTranscript changes mid-callLive captions, real-time monitoring
transfer_startedAn agent transfer beginsLog routing, notify agents
transfer_bridgedTransfer connectedUpdate call state
transfer_cancelledTransfer cancelledRevert routing state
transfer_endedTransfer completedReconcile call legs
chat_startedA chat session beginsTrack chat sessions
chat_endedA chat session endsPersist chat record
chat_analyzedPost-chat analysis completesStore chat summary, sentiment

Payloads carry an event field plus a call object (voice/transfer events) or a chat object (chat events). Dedupe on event + call.call_id (or chat.chat_id) — Retell retries up to 3 times if it doesn't get a 2xx within 10 seconds.

See references/overview.md for full payload structure.

Environment Variables

# The Retell API key (must have the webhook badge). Used as the HMAC secret.
RETELL_API_KEY=key_xxxxxxxxxxxxxxxxxxxxxxxx
PORT=3000

Local Development

For local webhook testing, run the Hookdeck CLI via npx — no install required:

npx hookdeck-cli listen 3000 retell --path /webhooks/retell

No account required — the CLI creates a guest account on first run and provides a local tunnel + web UI for inspecting requests.

Resources

  • Overview - What Retell webhooks are, event types, payloads
  • Setup - Configure account-level and agent-level webhooks
  • Verification - Signature verification details and gotchas
  • Express Example - Complete Express.js implementation
  • Next.js Example - Next.js App Router implementation
  • FastAPI Example - Python FastAPI implementation (uses the Retell SDK)

Recommended: webhook-handler-patterns

We recommend installing the webhook-handler-patterns skill alongside this one for handler sequence, idempotency, error handling, and retry logic. Key references (open on GitHub):

Related Skills

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.