ProdgatorDocs
Administration

Outbound webhooks

Send organization-wide notifications to your own HTTPS endpoint, verify the signature, and rotate the secret.

Availability

Business plan and above. Admins set up endpoints in Admin Console > Notifications. Webhooks do not appear there on Free or Team.

Outbound webhooks

On the Business and Enterprise plans, admins can have Prodgator POST organization-wide notifications to their own HTTPS endpoints. Open Admin Console > Notifications and add an endpoint with its URL, an optional description, and the categories to send.

Prodgator shows the endpoint's signing secret () once. Store it; you need it to verify deliveries.

Payload

{
  "type": "notification.pipeline_failure",
  "timestamp": "2026-09-28T12:00:00.000Z",
  "data": {
    "id": "...",
    "orgId": "...",
    "category": "pipelineFailure",
    "type": "pipeline_failure",
    "severity": "critical",
    "title": "...",
    "message": "...",
    "url": "https://app.prodgator.io/app/...",
    "sourceType": "pipeline_run",
    "sourceId": "...",
    "createdAt": "..."
  }
}

Send test posts to the endpoint.

Verifying the signature

Each request carries three headers:

HeaderValue
Unique message ID
Unix time in seconds
One or more space-separated values

To verify:

  1. Take the secret, drop the prefix and base64-decode the rest. That is the HMAC key.
  2. Compute HMAC-SHA256 over and base64-encode it.
  3. Accept the request if it matches any value, and the timestamp is within 5 minutes of now.

This is the Standard Webhooks scheme, so their libraries work too.

Rotating and failures

  • Rotate secret creates a new secret. For the next 24 hours each delivery is signed with both the old and new secret, so you can switch without dropping requests.
  • The delivery log shows recent attempts with their HTTP status.
  • Prodgator disables an endpoint after 10 failed deliveries in a row, if it returns , or if its host resolves to a private or blocked address. It then notifies your organization.

On this page