Integrate
Webhooks
Webhooks tell your own systems when something happens in your fleet. Every delivery is signed, retried on failure and recorded.
Events
Subscribe an endpoint to any of these events. An event name that is not on this list is refused when you save the webhook, so a typo never silently subscribes to nothing.
instance.startedinstance.stoppedinstance.crashedinstance.recoveredinstance.recovery_failedhost.offlinehost.onlinebackup.completedbackup.failedrollout.completedrollout.pausedconfig.appliedconfig.driftedcredit.lowalert.openedalert.resolved
Verifying deliveries
Every delivery carries an X-Webhook-Timestamp header and an X-Webhook-Signature header. The signature is v1= followed by the hex HMAC-SHA256 of <timestamp>.<body>, keyed with the webhook's signing secret. Verify it, and check the timestamp is recent, before trusting the body.
When you rotate the signing secret, deliveries are signed with both the new and the old secret for 24 hours, so you can switch your verifier over without dropping events.
Retries
A delivery that fails is retried 5 more times, waiting 1 min, 5 min, 30 min, 2 h, 6 h between attempts.
An endpoint that keeps failing is never switched off for you. Instead, repeated failures raise a webhook.failing alert, so you decide what to do.
Delivery log, redelivery and replay
- The delivery log shows every attempt and its response.
- Redeliver sends a past delivery again.
- Replay sends past events again as new events, each with a new event id, so deduplicate on your side by the fields that matter to you rather than by event id alone.
- Test sends a sample delivery to check an endpoint before you rely on it.