Skip to content
App

Developers

Webhooks

Receive scan and finding events, and verify signatures correctly.

Register an endpoint per workspace. Every delivery is signed with HMAC-SHA256 over the raw request body using your webhook secret.

Verifying a delivery

ts
import { createHmac, timingSafeEqual } from "node:crypto";

export function verify(rawBody: string, signature: string, secret: string) {
  const expected = createHmac("sha256", secret).update(rawBody).digest("hex");
  return timingSafeEqual(Buffer.from(signature), Buffer.from(expected));
}

Events

  • scan.started, scan.completed, scan.failed
  • finding.created, finding.resolved
  • document.published
  • monitor.drift_detected

Deliveries retry with exponential backoff for 24 hours. Respond 2xx within ten seconds and process asynchronously.

Was this page helpful?