Skip to content
DocumentationDevelopersOutbound webhooks
DevelopersCurrent contractVersion DOCS-2.0

Outbound webhooks

Signed events, bounded retries, fail-closed behavior and anti-SSRF protections.

How to interpret this document

This content describes technical and methodological behavior that is implemented or explicitly planned in the product. When a control depends on configuration, a provider, a secret, a contract or legal approval, that dependency must remain visible.

Events

Current events include measurement.completed, measurement.failed, recommendation.updated, alert.updated and billing.invoice.paid.

Signing

When WEBHOOK_SIGNING_SECRET is configured, the endpoint secret is derived from the runtime master secret and endpoint ID. Delivery signatures use HMAC-SHA256 over timestamp + payload.

Fail closed

Without WEBHOOK_SIGNING_SECRET, new webhook registration remains blocked instead of delivering unsigned callbacks.

SSRF protection

Endpoints require HTTPS; localhost, private ranges, .local names and DNS resolving to private IPv4 ranges are rejected; redirects are disabled.

Retry

The worker uses bounded attempts and backoff. Receiver response bodies are not persisted, reducing accidental ingestion of third-party data.

Idempotency

WebhookDelivery uses a key derived from endpoint, event type and event ID to prevent duplicate enqueueing for the same destination.