Administration
Outbound webhooks
Send organization-wide notifications to your own HTTPS endpoint, verify the signature, and rotate the secret.
Availability
Business plan and above. Admins set up endpoints in Admin Console > Notifications. Webhooks do not appear there on Free or Team.
Outbound webhooks
On the Business and Enterprise plans, admins can have Prodgator POST organization-wide notifications to their own HTTPS endpoints. Open Admin Console > Notifications and add an endpoint with its URL, an optional description, and the categories to send.
Prodgator shows the endpoint's signing secret () once. Store it; you need it to verify deliveries.
Payload
{
"type": "notification.pipeline_failure",
"timestamp": "2026-09-28T12:00:00.000Z",
"data": {
"id": "...",
"orgId": "...",
"category": "pipelineFailure",
"type": "pipeline_failure",
"severity": "critical",
"title": "...",
"message": "...",
"url": "https://app.prodgator.io/app/...",
"sourceType": "pipeline_run",
"sourceId": "...",
"createdAt": "..."
}
}Send test posts to the endpoint.
Verifying the signature
Each request carries three headers:
| Header | Value |
|---|---|
| Unique message ID | |
| Unix time in seconds | |
| One or more space-separated values |
To verify:
- Take the secret, drop the prefix and base64-decode the rest. That is the HMAC key.
- Compute HMAC-SHA256 over and base64-encode it.
- Accept the request if it matches any value, and the timestamp is within 5 minutes of now.
This is the Standard Webhooks scheme, so their libraries work too.
Rotating and failures
- Rotate secret creates a new secret. For the next 24 hours each delivery is signed with both the old and new secret, so you can switch without dropping requests.
- The delivery log shows recent attempts with their HTTP status.
- Prodgator disables an endpoint after 10 failed deliveries in a row, if it returns , or if its host resolves to a private or blocked address. It then notifies your organization.