Feature

Zuuna and n8n, in both directions

n8n reads and writes Zuuna over the REST API, Zuuna sends signed webhooks back. Three real directions, no ready-made node needed.

Last updated:

n8n and Zuuna talk in both directions, through plain HTTP building blocks rather than a ready-made connector. One direction needs an API token, the other a webhook node in your workflow.

Three directions, and all three are real

n8n to Zuuna

With a scoped token, your workflow creates cards, posts comments and logs time, all through the HTTP Request node. A bearer token in the header is enough, no OAuth dance.

POST https://app.zuuna.de/api/v1/boards/BOARD_ID/cards
Authorization: Bearer zk_live_...
Content-Type: application/json

{ "title": "New task", "idempotencyKey": "order-4711-card" }

idempotencyKey is any string you choose. Run the same workflow twice with the same value and the second call returns the card the first one created instead of a duplicate. That makes a retry in the workflow safe.

Zuuna to n8n

Zuuna sends signed webhooks to a Webhook node in your workflow. Every delivery carries the header X-Zuuna-Signature, an HMAC-SHA256 of the raw body keyed with your endpoint's secret.

import { createHmac, timingSafeEqual } from "crypto";

function verify(rawBody, header, secret) {
  const expected = "sha256=" +
    createHmac("sha256", secret).update(rawBody).digest("hex");
  const a = Buffer.from(header || "");
  const b = Buffer.from(expected);
  return a.length === b.length && timingSafeEqual(a, b);
}

The check runs over the exact raw bytes as they arrive, never over a JSON body that was parsed and re-serialized first. A code node that touches the bytes before checking shifts key order or escapes, and every signature fails.

Zuuna to n8n as a deploy target

A release you publish can trigger your n8n workflow directly. n8n is one of the targets a deploy target can point at, alongside GitHub, GitLab, Jenkins or a plain webhook.

Three recipes to copy

  • A form or an email becomes a card. A form or email trigger in n8n, an HTTP Request node behind it that creates the card.
  • A moved card becomes a message in your team tool. Zuuna sends card.moved, n8n turns it into a message for Slack, Discord, Teams or whatever you use.
  • Every logged hour becomes a row in your spreadsheet. time.logged as the trigger, a node that writes the row into Google Sheets, Airtable or your own database.

Plan

The REST API and outbound webhooks belong to the Developer plan. If you only want to post to an endpoint from a single action, say on every card move, you do not need an API token for that: automations already do it from the Plus plan.

FAQ

Do I need a ready-made n8n node?

No. The HTTP Request node covers everything n8n can trigger on Zuuna, as shown in the examples above.

How do I check the signature?

HMAC-SHA256 over the raw body with your endpoint's secret, compared against the X-Zuuna-Signature header in the format sha256=hex. The code sample above runs unchanged inside an n8n Code node. Check the bytes as they arrive, never a re-serialized JSON body.

Can n8n create boards?

Yes, with the boards:write scope, as long as whoever created the token holds that permission themselves. The API cannot create a new group; that has to exist already.

Which plan?

The REST API and webhooks belong to the Developer plan. Posting to an endpoint already works from the Plus plan through automations.

See it on your own board.

Create a board and try the feature with real cards (14 days of full access, no credit card).