Workflow builder
Connect procuris to Teams and Excel without software of your own, step by step in Make and Power Automate.
You receive this service through an individual quote.
A workflow builder connects programs through building blocks instead of programming. With it, a new hit of your saved searches with title, deadline and Fit becomes a message in Teams or a row in an Excel table. procuris sends a message to the builder for this, a webhook, and the builder passes it on.
A workflow builder is enough for simple flows. For a CRM, we recommend a small service of your own instead of a workflow builder, because the sync needs a queue and a comparison of states, see CRM and ERP.
Which builder works
We recommend Make, because it checks itself that a message is genuine. procuris signs every webhook message with a secret key, the secret. If your flow checks this signature, no outsider can slip it an invented message. However, someone who intercepted a genuine message on the way can send it again, see Duplicate messages.
| Builder | Check authenticity with built-in building blocks | Recommendation |
|---|---|---|
| Make | yes, with the built-in formula sha256 | first choice, recipe below |
| Power Automate | no, there is no function for HMAC-SHA256, the calculation method of the signature. Protection only through the secret address of the flow. | only with a suitable license, see recipe below |
| n8n | no. The Crypto node accepts the secret only as text, but the procuris key is binary, that is, not a readable string. | use Make |
| Zapier | no. Formatter by Zapier offers date, text, numbers and utilities, but no HMAC check. | use Make |
The role Owner makes the entries in procuris. The person with this role manages endpoints and the secret in procuris under Settings › Organization › Webhooks. The section exists only once access has been set up after the contract is signed. Until then, the Webhooks row in the On request section of the same page only requests a quote. If you do not have the role Owner yourself, ask the owner for the entries the recipe names. Integrations describes the way from the request to the set-up access.
Recipe: new hit in Teams and Excel with Make
Create a scenario and turn on raw data. In Make, create a new scenario with the first module Webhooks › Custom webhook, then Add for a new webhook. In the advanced settings of the webhook, turn on JSON pass-through and Get request headers. A message consists of headers and a body. The headers are accompanying details such as the signature. The body is the actual content, that is, title, deadline and the other details. With these settings, the body arrives unchanged as text, and the authenticity check needs exactly this text. Make offers single fields such as title or deadline only after the step Parse the body. The headers are available as a list.
Create the endpoint in procuris. Make shows the address of the webhook. The owner creates it under Webhooks as an endpoint and chooses the event search.hit and the saved searches whose hits should arrive.
Fetch a test message. In Make, run the scenario once. Then the owner chooses Send test message on the endpoint under Webhooks in procuris. Make then shows the headers and the body as text. You set up the next steps with these values.
Read the headers. A header is an entry with name and value in the list of headers. You get the value of a header with this formula, here for webhook-signature:
get(map(<header list>; value; name; webhook-signature); 1)
map takes from the list the values of the entries whose name is webhook-signature. get(…; 1) takes the first of them. The same works for webhook-id and webhook-timestamp.
Get the secret. The secret comes from the owner. procuris shows it to them under Webhooks on the endpoint, in the form whsec_ followed by letters and digits. Every endpoint has a secret of its own. The owner passes it to you through a password manager, not by email or chat. For the next step, you need only the part after whsec_.
Check authenticity. Directly after the webhook, add a filter: the value of webhook-signature (formula above), condition Contains, comparison value:
v1,{{sha256(<webhook-id>.<webhook-timestamp>.<body>; base64; <secret without whsec_>; base64)}}
For <webhook-id> and <webhook-timestamp>, insert the formula from step 4. For <body>, choose the field with the unchanged body from the webhook. A dot goes between each of the three parts. For <secret without whsec_>, insert the part of the secret after whsec_ from the previous step. Text in Make formulas stands without quotation marks. Only genuine messages pass the filter.
Parse the body. Module JSON › Parse JSON. In JSON string, choose the field with the body from the webhook. Under Data structure, choose Add, then Generator. Paste the example "search.hit, complete" from the Events page into the field Sample data and choose Save. Give the structure a name, for example "procuris hit", and choose Save again. Make then knows the whole structure of the message. type, data.tender.title, data.tender.submissionDate, data.tender.url, data.search.name and data.fit are available for selection.
Hits only. Add a second filter: type is equal to search.hit. This keeps test messages and other events out of Teams.
Message and row. A module for Microsoft Teams that sends a message to a channel, for example "New hit: title, deadline, Fit, link". Next to it, a module for Excel that adds a row to a table. Columns for example title, deadline, Fit, link and webhook-id. Fill the column webhook-id with the formula from step 4. It helps against duplicate rows.
Catch failures. In the scenario settings, turn on Store incomplete executions. If a step fails after that, Make keeps the run as an incomplete execution. According to its own help, Make retries it automatically only for three kinds of error: RateLimitError (too many requests), ConnectionError (connection failed) and ModuleTimeoutError (a module responds too late). For other errors, for example an Excel table that no longer exists, rerun the execution in Make by hand after you have fixed the cause.
Test the flow
The test message does not pass the filter from step 8. It carries the value webhook.test as type. To check Teams and Excel without a real hit, temporarily change the comparison value in the filter from step 8 to webhook.test. Then the owner sends a test message. It contains a sample tender with title, deadline, link and a Fit of 82. Teams therefore shows a complete message, and Excel gets a row. Afterwards, set the comparison value back to search.hit and delete the test row in Excel.
Rotate the secret
A secret rotation can cost messages in Make. Make confirms receipt to procuris with 200 before the filter checks. If the filter does not let a message through, procuris still treats it as delivered. procuris then does not retry it. The message is lost.
- Planned rotation: The owner chooses Renew secret on the endpoint under Webhooks and passes the new secret to you. Enter it in the filter from step 6 within 24 hours. During these 24 hours, every message carries one signature with the old and one with the new secret. The filter therefore lets it through with either. After 24 hours, only the new one is valid. A filter with the old secret then silently discards every message.
- Secret that has become public: The owner chooses Replace secret now. The old secret is no longer valid from then on, without a transition. Until the new one is in the filter, Make silently discards every message. Enter it right away for this reason. Then the owner resends the messages from the last 7 days under Webhooks. This brings the lost ones back. The resend can also contain messages that already got through, see Duplicate messages.
Duplicate messages
A message can arrive twice. This happens when the owner resends messages. It also happens when someone intercepts a genuine message and sends it again, because this recipe does not check the timestamp of the message. A duplicate message carries the same webhook-id as the original.
Teams then shows a second message, and Excel gets a duplicate row. For a Teams channel this is acceptable, because a second message there changes nothing. In Excel, however, a duplicate row can distort totals and counts. After a resend, check the webhook-id column for this reason and delete rows with a webhook-id that already appears.
Recipe: new hit in Teams and Excel with Power Automate
Power Automate cannot check the signature. Only its secret address protects the flow, which contains a key in the part sig=. Anyone who knows the address can send messages to the flow.
Microsoft 365 licenses cover standard connectors only. According to Microsoft, this also applies to the free license Power Automate Free. Premium connectors come, for example, with the license Power Automate Premium. You check yourself, without IT, whether your license is enough for this recipe. Your license is shown in Power Automate under Settings › View my licenses, in the section My licenses. If the trigger When an HTTP request is received carries the label Premium when you add it and you only have Power Automate Free or a Microsoft 365 license, your license is not enough.
Create a flow. A new cloud flow with the trigger When an HTTP request is received. Under Who can trigger the flow, choose Anyone, because procuris does not sign in to your Microsoft account.
Store the structure. Choose Use sample payload to generate schema and paste the example
for search.hit from the Events page.
Create the endpoint in procuris. After saving, the trigger shows the address of the flow.
The owner creates it under Webhooks as an endpoint and chooses the event search.hit and
the saved searches whose hits should arrive. Do not give the address to anyone else, because it
is the only protection of the flow.
type is equal to search.hit.Teams message. Action Post message in a chat or channel, Post as Flow bot, Post in Channel, message with title, deadline, Fit and link from the fields of the message.
Excel row. Action Add a row into a table in an Excel file on OneDrive or SharePoint. The
data must be in an Excel table, not only on a sheet. Columns for example title, deadline, Fit,
link, procuris ID and webhook-id. Fill the column webhook-id with the expression
triggerOutputs()['headers']['webhook-id']. It helps against duplicate rows.
Catch failures. Use Run after to add an error branch, for example an email if the Teams message fails. Flow owners also receive emails from Microsoft for serious errors.
Test the flow. In the Condition, temporarily change the comparison value to
webhook.test. The owner sends a test message. Teams and Excel show the sample tender.
Afterwards, set the comparison value back to search.hit and delete the test row in Excel.
Power Automate also creates duplicate rows after a resend. If the owner resends messages, each arrives again with the same webhook-id. The flow then adds a second row and sends a second Teams message. After a resend, check the webhook-id column for this reason and delete rows with a webhook-id that already appears, as with Make under Duplicate messages.
An address that has become known needs a new key. Power Automate renews it only through the developer tools of the browser. Leave that to your IT, following the Microsoft guide "Regenerate the SAS key used in HTTP trigger flows". Then the owner changes the endpoint under Webhooks to the new address.
If the flow fails
An error after receipt stays with the builder. Make and Power Automate confirm receipt to procuris as soon as the message has arrived. If a step fails after that, procuris treats the message as delivered, and it does not arrive again. That is why the error handling of the builder belongs in both recipes.
If the builder itself is unreachable, procuris retries the delivery. The attempts run over a little over three days, see Delivery and security. If no delivery to the endpoint succeeds for 5 days, procuris stops delivery there and writes to the owner. Once the builder runs again, the owner chooses Resume delivery on the endpoint under Webhooks and resends the missed messages from the last 7 days.
Related pages
Request a quote
Tell us what you want to use or connect. Your quote is based on that scope.
CRM and ERP
New matching tenders automatically as sales opportunities in the CRM, deadlines and values in the ERP, with field mapping and protection against duplicates.
Single sign-on
Sign in to procuris with the company account through SAML 2.0 or OpenID Connect, create and lock out accounts automatically, values for Microsoft Entra ID and Google Workspace.