Skip to main content
Question

Is there a way to protect a Catch Hook Trigger with an API Key?

  • August 29, 2025
  • 0 replies
  • 0 views

Forum|alt.badge.img+1

Goal: I am looking for a way to send more than one event per request to a webhook in a way where I can check a header value from the request, find an API key there, and compare it to an API key I’m storing on Zapier’s end.

 

My approach so far:
I’ve read a bunch of posts from devs talking about how Zapier does not provide a way to protect webhooks with API keys or other forms of authentication.

To get around that, I’m storing a key in Storage By Zapier, and I’d like to compare the key in storage with a key stored in a header value of the request to the webhook. This seems to work.

I’d also like to send more than one event per request, like in this example: https://help.zapier.com/hc/en-us/articles/8496288690317-Trigger-Zaps-from-webhooks#h_01HBGES5DWXFNY7YWR19877NC1

The Catch Hook Trigger could handle this multi-event case, but it does not give me a way to access the headers of the request.

Catch Hook Raw Trigger gives me access to the headers of the request, but it does not parse the JSON.

I attempted to parse the json using Code For Zapier, but the output only gives me the first event in the list of events. Here’s my python code:

 

import json
output = json.loads(inputData['rawData']);


So for the input:
[
{ “Id”: 1, “Name”: “John”},

{“Id”: 2,  “Name”: “Janet”},

{“Id”: 3,  “Name”: “Hugo”},
]

The output is just:

Id: 1
Name: John

The latter two objects are dropped.

Is there any way to accomplish what I’m trying to do?

This post has been closed for comments. Please create a new post if you need help or have a question about this topic.