# Custom Webhook Action – Secure Credential Management

> This guide walks you through the latest improvements to the Custom Webhook action, focusing on enhanced security measures and streamlined credential…

- Source: https://docs.ghlcustomercare.com/docs/workflows/getting-started-w-workflows/custom-webhook-action-secure-credential-management
- Section: Workflows / Getting Started w/ Workflows
- Reading time: 2 min
- Images: 5, each explained below
- Modified on Mon, 14 Apr, 2025 at 10:07 AM

---
This guide walks you through the latest improvements to the Custom Webhook action, focusing on enhanced security measures and streamlined credential management.

---

**TABLE OF CONTENTS**

-   [Overview](#overview)
-   [Key Improvements](#key-improvements)
    -   [Masked Secret Keys](#masked-secret-keys)
    -   [User-Friendly Credential Management](#user-friendly-credential-management)
-   [Why These Updates Matter](#why-these-updates-matter)
-   [Getting Started](#getting-started)
-   [Important Notes](#important-notes)

---

## Overview

The Custom Webhook action now supports masked secret keys for Basic auth, Bearer token, and API key authentication methods. This update helps prevent the accidental exposure of sensitive information and provides an easier way to manage and store credentials.

---

## Key Improvements

### Masked Secret Keys

-   **Secure Storage**: All secret keys are securely stored and masked in the interface.
    
-   **Supported Auth Methods**: Basic auth, Bearer token, or API key.
    
-   **Reduced Exposure**: Keys are never displayed in plain text, minimizing the risk of leaks.
    

### User-Friendly Credential Management

-   **Key Management**: Select from existing keys or create a new key from a dropdown menu.
    
-   **Restricted Removal**: Only **agency admins** or **the creator of the key** can delete it.
    
-   **Location-Level Security**: Keys are accessible only within the location where they were created.
    

---

## Why These Updates Matter

1.  **Enhanced Security**
    
    -   Secret keys are masked to drastically lower the chances of accidental leaks.
        
    -   Keys are identified by name instead of their actual value, reducing risk.
        
2.  **Better Access Control**
    
    -   Sensitive credentials are editable only by users that have created and admins at the location level.
        

---

## Getting Started

Follow these steps to add and configure a new Custom Webhook action in your Automations builder.

1.  **Add a Custom Webhook Action**
    
    -   In your Automations builder, select **Custom Webhook** as the action step.
        
2.  **Select Authentication Type**
    
    -   Choose one of the following methods: **Basic auth**, **Bearer token**, or **API key**.
        
3.  **Configure Credentials**
    
    -   Choose **Create New Key**.
        
    -   Enter a **key name** (for identification) and the **key value** (the actual credential).
        
    -   Once saved, the key will be masked, so it won’t appear in plain text.
        
4.  **Monitor & Manage**
    
    -   Use the dropdown menu to select or delete keys as needed.
        

---

## Important Notes

-   **Deletion Permissions**: Only agency admins or the key’s creator can delete it.
    
-   **Existing Keys**: Once you update to a new key, old key will be automatically removed.
    

![Important Notes (image 1 of 5)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155045064373/original/d90fEX1tr4sa9wyPSUWh0U8BQVvguDAx3A.png)

**Important Notes (image 1 of 5)**

This screenshot appears in the "Important Notes" section of "Custom Webhook Action – Secure Credential Management". The text alongside this image reads: Deletion Permissions: Only agency admins or the key’s creator can delete it. Existing Keys: Once you update to a new key, old key will be automatically removed.
- What this covers: Deletion Permissions: Only agency admins or the key’s creator can delete it. Existing Keys: Once you update to a new key, old key will be automatically removed.
- Controls: Deletion Permissions, Existing Keys

Full procedure:

1. Deletion Permissions: Only agency admins or the key’s creator can delete it.
2. Existing Keys: Once you update to a new key, old key will be automatically removed.

![Important Notes (image 2 of 5)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155045064380/original/OzCNzq-qJdDKgQDDKd2d7-XQZtv-6ZU2tw.png)

**Important Notes (image 2 of 5)**

This screenshot appears in the "Important Notes" section of "Custom Webhook Action – Secure Credential Management". The text alongside this image reads: Deletion Permissions: Only agency admins or the key’s creator can delete it. Existing Keys: Once you update to a new key, old key will be automatically removed.
- What this covers: Deletion Permissions: Only agency admins or the key’s creator can delete it. Existing Keys: Once you update to a new key, old key will be automatically removed.
- Controls: Deletion Permissions, Existing Keys

Full procedure:

1. Deletion Permissions: Only agency admins or the key’s creator can delete it.
2. Existing Keys: Once you update to a new key, old key will be automatically removed.

![Important Notes (image 3 of 5)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155045064383/original/BPZy4-09gQZDgA5rETgzBp5cfL2uF-a4MQ.png)

**Important Notes (image 3 of 5)**

This screenshot appears in the "Important Notes" section of "Custom Webhook Action – Secure Credential Management". The text alongside this image reads: Deletion Permissions: Only agency admins or the key’s creator can delete it. Existing Keys: Once you update to a new key, old key will be automatically removed.
- What this covers: Deletion Permissions: Only agency admins or the key’s creator can delete it. Existing Keys: Once you update to a new key, old key will be automatically removed.
- Controls: Deletion Permissions, Existing Keys

Full procedure:

1. Deletion Permissions: Only agency admins or the key’s creator can delete it.
2. Existing Keys: Once you update to a new key, old key will be automatically removed.

![Important Notes (image 4 of 5)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155045064392/original/1SUoBaiQVlKf3CIzrZSPHUG_dZ41O4DkHg.png)

**Important Notes (image 4 of 5)**

This screenshot appears in the "Important Notes" section of "Custom Webhook Action – Secure Credential Management". The text alongside this image reads: Deletion Permissions: Only agency admins or the key’s creator can delete it. Existing Keys: Once you update to a new key, old key will be automatically removed.
- What this covers: Deletion Permissions: Only agency admins or the key’s creator can delete it. Existing Keys: Once you update to a new key, old key will be automatically removed.
- Controls: Deletion Permissions, Existing Keys

Full procedure:

1. Deletion Permissions: Only agency admins or the key’s creator can delete it.
2. Existing Keys: Once you update to a new key, old key will be automatically removed.

![Important Notes (image 5 of 5)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155045064424/original/0OvsqZI1JfmGPxEE5Nnz7WX1ACOuw0Mf3A.png)

**Important Notes (image 5 of 5)**

This screenshot appears in the "Important Notes" section of "Custom Webhook Action – Secure Credential Management". The text alongside this image reads: Deletion Permissions: Only agency admins or the key’s creator can delete it. Existing Keys: Once you update to a new key, old key will be automatically removed.
- What this covers: Deletion Permissions: Only agency admins or the key’s creator can delete it. Existing Keys: Once you update to a new key, old key will be automatically removed.
- Controls: Deletion Permissions, Existing Keys

Full procedure:

1. Deletion Permissions: Only agency admins or the key’s creator can delete it.
2. Existing Keys: Once you update to a new key, old key will be automatically removed.

---

Documentation for GHL Customer Care. Support: support@ghlcustomercare.com