Connect RudderStack

Connect RudderStack to give its Webhook destination a Squoosh endpoint for event delivery. This page covers setup from Integrations and the limits of the current connection.

Beta: surface stage

This connector has not been validated against a live account. Squoosh authenticates incoming requests, validates their JSON transport shape, acknowledges them, and discards the event payload. It records a periodic delivery heartbeat. It does not store events, produce analytics, or change how your AI shoppers behave.

Saving creates an Endpoint ready / Awaiting delivery connection. A current-key authenticated delivery heartbeat establishes transport health. Checking status cannot verify a key, and rotating the key requires a new delivery. Payloads remain discarded and no calibration numbers are produced.

What the connection does

RudderStack sends events to Squoosh; Squoosh does not call a RudderStack reporting API. A successful request receives HTTP 202 with {"accepted": true}. Acceptance confirms receipt and disposal, not storage or aggregation.

The connection's status check confirms only that the connection surface exists. It does not test your RudderStack destination, credentials, or event flow. Device, geography, traffic source, and conversion analysis remain future capabilities. No calibration snapshot or conversion rate is available.

Connect RudderStack

Use the classic Webhook destination as the recommended setup. Squoosh generates a shared secret; you do not need a RudderStack Personal Access Token, Service Access Token, or source write key.

  1. In Squoosh, open Integrations, choose RudderStack, and click Connect. Generate the ingest URL and shared secret. Copy the secret immediately; Squoosh shows it once.
  2. In the RudderStack dashboard, open Destinations, add a Webhook destination, and connect the source whose events you want to send.
  3. Paste the complete Squoosh ingest URL, including ?connection=..., into Webhook URL. Keep URL Method set to POST.
  4. In Headers, add x-squoosh-rudderstack-secret as the key and the Squoosh shared secret as its value. Keep this secret out of the URL and event properties.
  5. Save and enable the destination. Send a test event from the connected source. Inspect the destination's Live Events tab for delivery results and Error Response details.

These fields and the full-event POST format are documented in RudderStack's Webhook setup guide and cloud-mode guide.

If you use HTTP Webhook

The newer HTTP Webhook destination has different screens. Its official setup and release pages disagree on availability, so check which destination your workspace offers.

  • Set Base URL to the complete Squoosh ingest URL, Method to POST, and Body Format to JSON.
  • Under Authentication, choose Bearer Token and paste the secret into Token. Alternatively, choose Basic Auth, use a username such as squoosh, and paste the secret into Password. The username alone cannot authenticate.
  • Keep Send the event payload as is enabled.
  • Leave Enable Batching off initially. If needed, set Maximum Batch Size to 30 or fewer to leave room under Squoosh's 1 MiB request cap. The provider allows up to 100 events; Squoosh accepts bare arrays of at most 100 objects only when the entire body fits the byte cap. Thirty is a precaution, not a guarantee after enrichment or transformations.

Use the Authentication setting for Basic or Bearer credentials. Do not rely on an API Key setting: its transport is unverified. Squoosh does not verify a RudderStack HMAC signature. See the HTTP Webhook setup guide and send-events guide.

Reconnecting

Reconnecting generates a new secret. Immediately replace the previous secret in the RudderStack destination's Headers row or Authentication setting. Events carrying the old secret receive 401 and are aborted by RudderStack without retry.

What Squoosh reads and never reads

Squoosh reads the connection identifier, the presented authentication header, the content type, and the bounded JSON body. It checks for an object or a bare array of objects and counts the objects in that request. It accepts unknown event types and mapped objects without requiring individual event fields. An empty array is acknowledged with a zero-event transport heartbeat; this proves authentication, not event activity.

The endpoint discards all event content, including identities, traits, URLs, and properties. It never stores the payload in snapshots, connection settings, logs, or the delivery heartbeat. It never calls a RudderStack API, fetches customer profiles or historical reports, follows transformation-injected URLs, or derives a distribution from events. A heartbeat records receipt at most once per connection per hour per server instance; it is not an event counter.

Limits and caveats

  • 1 MiB per request, measured in UTF-8 bytes, and at most 100 objects per bare array. A rejected batch is rejected as a whole; it is not clipped.
  • POST JSON only. GET and DELETE put event properties in URL parameters and are refused with 405. XML, form bodies, malformed JSON, scalar JSON, and non-object array elements are refused with 400.
  • Squoosh applies its shared per-connection ingest rate limit after authentication. A tripped limit returns 429 and Retry-After; a failure of the limiter itself does not reject authenticated traffic.
  • RudderStack retries 5xx and 429 for a window of up to three hours with exponential backoff. Other 4xx, including 400, 401, 405, and 413, are aborted without retry. A failing event can hold later events for the same user. See the retry FAQ.
  • No webhook request deadline is established in the cited documentation. This endpoint performs no event processing or vendor calls before acknowledging, but live delivery timing has not been validated.
  • There is no event storage, replay protection, historical backfill, deduplication, or aggregation in this stage. RudderStack event counts are not a session denominator. Squoosh never invents a conversion rate from them.
  • Future geography would require actual enriched geography fields; locale or timezone is not a substitute. The top-level channel names the SDK surface, not an acquisition channel. Neither is interpreted today.

Troubleshooting

Problem What to do
401 Unauthorized Check the complete ingest URL and the secret in Headers or Authentication. Confirm the connection is active. The same response covers an unknown connection, wrong provider, unreadable credentials, or wrong secret.
Events stop after reconnecting Replace the old secret in RudderStack immediately. Already aborted events are not recovered by reconnecting.
400 invalid_body Set Body Format to JSON and keep Send the event payload as is enabled. Send one object or a bare array of objects.
405 method_not_allowed Set URL Method or Method to POST.
413 payload_too_large Disable batching or reduce Maximum Batch Size. Reduce oversized event properties. The 1 MiB limit applies even below 100 events.
429 rate_limited Allow RudderStack to retry. Check event volume; Squoosh includes Retry-After.
503 temporarily_unavailable This indicates a transient Squoosh connection-lookup failure. Allow RudderStack to retry.
Connected but no heartbeat Check that the destination is enabled, the source is connected and sending events, and workspace processing has not stopped because of plan limits. Inspect Live Events for failures.
No calibration or conversion rate Expected in this beta stage. Receipt and heartbeat reporting are the only available capabilities.