IntegrationsEleven providers, one signed event stream

One reply, everywhere
your team already works.

Every event Muster fires rides one wire to your whole stack. A positive reply creates the lead in Close, pings Slack, fires a Zap, and POSTs your own endpoint, all at once. Connect over OAuth, an API key, or a webhook URL, then build the rest on a signed stream.

The wire

One event. Every destination.

Integrations are not bolt-on connectors that each poll for changes. Every state change publishes one internal event, and each connected tool subscribes to what it cares about. A single positive reply reaches your CRM, your team chat, your automation platform, and your own server in the same beat.

event fired
campaign.reply_received
"trigger": "positive_reply",
"contact": "rowan@northwind.co",
"campaign": "q1-outbound",
"mailbox": "ben@acme.com"
fans out to 4 subscribers
C
CloseCRM

The lead created in Close, ready for the calling queue.

S
SlackNotifications

A channel pinged with the prospect, mailbox, and thread.

Z
ZapierAutomation

Your Zap fires and branches across 8,000+ apps.

Your endpointWebhook

A signed POST lands on your own server in real time.

21 event types ride the same wireFan-out runs on the internal event queue
Connecting

Three ways in. One connect drawer.

The method follows the provider, not the other way around. OAuth where there is a per-user identity, an API key for account-scoped tools and automation platforms, and a minted webhook URL for inbound bookings. The drawer surfaces the right one; the flow is the same every time.

01
OAuth
Slack

A one-click authorization handshake. You approve scopes inside the provider, and Muster stores only the encrypted token. Revoke from either side at any time.

Token sealed with AES-256-GCM
02
API key
Close · Zapier · Make · n8n

For account-scoped tools and automation platforms. Paste a provider key, or mint a scoped Muster key for Zapier, Make and n8n to authenticate against your data.

Stored opaque, never returned
03
Webhook URL
Calendly · Cal.com · Discord

Muster mints an inbound URL per organization. Paste it into the provider, and their POSTs route to you by the secret in the path. Rotate it to invalidate instantly.

Per-org URL · rotate to revoke
Catalog

Eleven providers, four categories.

The whole directory the dashboard renders, in catalog order. Filter by what you are wiring up. Each tile shows the real authentication method, so you know what you will paste before you start.

C
Close
CRM
API key

Create the lead in Close when a prospect replies.

DocsConnect
Z
Zapier
Automation
API key

Triggers and actions across 8,000+ apps.

DocsConnect
M
Make
Automation
API key

Visual automation scenarios.

DocsConnect
n
n8n
Automation
API key

Self-hosted automation workflows.

DocsConnect
S
Slack
Notifications
OAuth

Real-time alerts for positive replies, bounces, and deliverability.

DocsConnect
D
Discord
Notifications
Webhook URL

Webhook-based notifications to a server channel.

DocsConnect
C
Calendly
Meetings
Webhook URL

Attribute booked meetings to the campaign that surfaced the lead.

DocsConnect
C
Cal.com
Meetings
Webhook URL

Same attribution path, open-source booking edition.

DocsConnect

Plus on-demand Google Sheets lead sync, which reads a spreadsheet into your contacts from the Contacts tab rather than the catalog.

Meetings

A booked meeting knows which campaign earned it.

Calendly and Cal.com are two different webhook shapes. Muster normalizes both into one booking record, joins it to the contact and the campaign that surfaced the lead, and fires a reply event so the rest of your stack treats a booking like the win it is.

  • One inbound URL per organization, minted for you. Paste it into the provider.
  • invitee.created and BOOKING_CREATED become one record.
  • Reporting credits the meeting to the sequence and mailbox that opened the door.
Calendly · invitee.created
inbound webhook received
booked
Inviteerowan@northwind.co
Event30 min intro
ScheduledJun 12 · 4:00 PM
Campaignq1-outbound
emitted event
{
"event_type": "campaign.reply_received",
"trigger": "meeting_booked",
"source": "calendly",
"campaign_id": "cmp · q1-outbound"
}
Calendly + Cal.com → one recordcredited to the campaign
Webhooks & API

Not on the list? Subscribe to the stream.

21 event types, signed with HMAC-SHA256 in the same format Stripe uses, retried with capped exponential backoff, and recorded with full delivery history per endpoint. Subscribe to everything, or filter to the handful you act on.

  • X-Muster-Signature: t=<unix>,v1=<hex> on every POST.
  • Per-endpoint filter by event type.
  • Rotate a secret and the old one dies immediately.
Read the developer docs
POST your endpointapplication/json
POST /your/webhook  HTTP/1.1
X-Muster-Signature: t=1748443269,v1=9f2a…c1b7

{
  "id": "f4a07e0c-a4b1-4dc8-9c5d-2c1b3e29c7b1",
  "event_type": "campaign.reply_received",
  "organization_id": "8c4e7c3d-…",
  "created_at": "2026-05-28T14:21:09Z",
  "data": { "trigger": "positive_reply", "campaign": "q1-outbound" }
}
Event types
21 live
Account2
email_account.connectedA mailbox finished onboarding.
email_account.removedA mailbox left the workspace.
Campaign12
campaign.email_sentA sequence step dispatched to a recipient.
campaign.email_deliveredThe receiver acknowledged delivery.
campaign.email_openedOpen pixel resolved. Unreliable at scale.
campaign.email_clickedA tracked link was clicked, deduped per recipient.
campaign.email_bouncedHard or soft bounce. Suppression follows.
campaign.reply_receivedA prospect replied, or a meeting was booked.
campaign.unsubscribedOne-click unsubscribe or a STOP reply.
campaign.startedCampaign moved into the running state.
campaign.pausedAuto-paused on a spike, or paused by hand.
campaign.completedThe last step dispatched for the last recipient.
campaign.deliverability_warningA campaign tripped a deliverability guardrail.
campaign.actionA sequence action node executed.
Warmup5
warmup.email_sentA warmup message went out to a pool partner.
warmup.health_changedA mailbox moved between health states.
warmup.placement_in_spamA warmup probe landed in junk.
warmup.quarantinedMailbox dropped to the recovery pool. 7-day cooldown.
warmup.blockedMailbox hard-blocked from the pool. 30-day cooldown.
Deliverability2
deliverability.bounceAn external bounce event was ingested.
deliverability.complaintAn external complaint event was ingested.
Delivery

What happens after we POST you.

A webhook you cannot trust or cannot recover is not a webhook. Every delivery is signed so you can verify it, retried so a blip never costs you an event, deduped so a retry never doubles up, and recorded so you can replay it.

Capped exponential backoff
non-2xx → retry · doubles each time · cap 1h · 8 attempts
30ssend
1mretry 1
2mretry 2
4mretry 3
8mretry 4
16mretry 5
32mretry 6
1hretry 7
first attemptbackoff windowfinal attempt, then given up
HMAC-SHA256 signed
X-Muster-Signature

Every POST carries t=<unix>,v1=<hex>, the same scheme Stripe uses. Verify the digest before you trust the body.

Retried with backoff
up to 8 attempts

A non-2xx doubles the wait each try, capped at one hour, then gives up. Nothing is dropped silently.

Idempotent + deduped
replay-safe

Each delivery carries a stable id, and SKIP LOCKED keeps two replicas from fanning the same event out twice.

Full audit trail
every attempt

Status, response, and a body excerpt are recorded per attempt. Replay any delivery from the dashboard.

Security

Credentials are sealed, not stored.

Integration credentials are sealed with your organization's data key. That key is sealed by a master key held outside the database, and only the sealed copy is stored.

OAuth tokens encrypted at rest

AES-256-GCM with a per-organization data key, sealed by a master key held outside the database. The unsealed key is cached for at most 15 minutes.

API keys are opaque blobs

CRM, automation and notification keys are never serialized back to the API. The dashboard sees only public display fields.

Inbound URLs are per-organization

A leaked URL touches one organization. Rotating the secret invalidates the old path immediately.

SSRF-guarded by default

Outbound webhook targets are HTTPS-only and blocked from obvious internal addresses.

Integrations FAQ

The questions we get a lot.

More detail in the developer docs.

Every state change Muster makes publishes one internal event. Connected integrations and your own webhook endpoints each subscribe to the event types they care about, and the fan-out runs on an internal queue. A single campaign.reply_received can create a Close lead, ping Slack, fire a Zap, and POST your endpoint, all from one reply.

No, and on purpose. OAuth is used where the provider exposes a per-user identity, as Slack does. Account-scoped tools like Close, and automation platforms like Zapier, Make and n8n, authenticate with an API key. Calendly, Cal.com and Discord use a webhook URL. The connect drawer picks the right method per provider.

The connection moves to a degraded state and the dashboard surfaces the provider error. Degraded connections stop attempting new fan-out until you rotate the key or re-authenticate, so a dead token never silently drops events on the floor.

Calendly POSTs invitee.created and Cal.com POSTs BOOKING_CREATED to the URL we mint. Both are normalized into one booking record, joined to the originating contact and campaign, and a campaign.reply_received fires with trigger=meeting_booked so downstream subscribers see which sequence earned the meeting.

Yes. A connection is unique per organization, provider and label, so you can hold a Slack connection per channel side by side.

Subscribe to the webhook stream and build it directly, or route it through Zapier, Make or n8n. The twenty-one event types cover every state transition Muster emits internally, each HMAC-signed in the same format Stripe uses.

Wire Muster into your stack.

Connect a provider in two clicks, or subscribe to the signed event stream and build the integration yourself.