Developers
Webhooks
Receive scan and finding events, and verify signatures correctly.
Register an endpoint per workspace. Every delivery is signed with HMAC-SHA256 over the raw request body using your webhook secret.
Verifying a delivery
ts
import { createHmac, timingSafeEqual } from "node:crypto";
export function verify(rawBody: string, signature: string, secret: string) {
const expected = createHmac("sha256", secret).update(rawBody).digest("hex");
return timingSafeEqual(Buffer.from(signature), Buffer.from(expected));
}Events
- scan.started, scan.completed, scan.failed
- finding.created, finding.resolved
- document.published
- monitor.drift_detected
Deliveries retry with exponential backoff for 24 hours. Respond 2xx within ten seconds and process asynchronously.
Was this page helpful?
