Outbound webhooks
Signed events, bounded retries, fail-closed behavior and anti-SSRF protections.
How to interpret this document
This content describes technical and methodological behavior that is implemented or explicitly planned in the product. When a control depends on configuration, a provider, a secret, a contract or legal approval, that dependency must remain visible.
Events
Current events include measurement.completed, measurement.failed, recommendation.updated, alert.updated and billing.invoice.paid.
Signing
When WEBHOOK_SIGNING_SECRET is configured, the endpoint secret is derived from the runtime master secret and endpoint ID. Delivery signatures use HMAC-SHA256 over timestamp + payload.
Fail closed
Without WEBHOOK_SIGNING_SECRET, new webhook registration remains blocked instead of delivering unsigned callbacks.
SSRF protection
Endpoints require HTTPS; localhost, private ranges, .local names and DNS resolving to private IPv4 ranges are rejected; redirects are disabled.
Retry
The worker uses bounded attempts and backoff. Receiver response bodies are not persisted, reducing accidental ingestion of third-party data.
Idempotency
WebhookDelivery uses a key derived from endpoint, event type and event ID to prevent duplicate enqueueing for the same destination.