Verify the signature in n8n
Add a Crypto node after the Webhook: action HMAC, type SHA256, secret = your IntoCal endpoint secret, value = the raw request body. Then use an IF node to compare "sha256=" + result with the X-IntoCal-Signature header and stop on mismatch.
// Code node alternative
const crypto = require('crypto');
const sig = 'sha256=' + crypto
.createHmac('sha256', $env.INTOCAL_SECRET)
.update(JSON.stringify($json.body))
.digest('hex');
return [{ json: { valid: sig === $json.headers['x-intocal-signature'] } }];Workflow recipes
- Lead enrichment: booking → look up company → write to Postgres and your CRM.
- AI meeting prep: booking → LLM summary of answers → email the host one hour before.
- Ops routing: booking for "support-call" → create a ticket in your helpdesk.
- Sync to an internal tool via HTTP or database node.
Calling the IntoCal API from n8n
Use an HTTP Request node against https://api.intocal.com/v1 with header Authorization: Bearer sk_live_... . POST requests that create bookings require an Idempotency-Key header so retries never double-book.
