ProdgatorDocs
Organization

Outbound webhooks

Send organization-wide notifications to your own HTTPS endpoint, verify the signature, and rotate the secret.

Pas encore traduite. Cette page est affichée en anglais. Lire l’original en anglais.

Availability

Business plan and above. Org admins set up endpoints in Organization > Notifications. Webhooks do not appear there on Free or Team.

Who can use this: Org admin only. See Roles.

Outbound webhooks

On the Business and Enterprise plans, Org admins can have Prodgator POST organization-wide notifications to their own HTTPS endpoints. Open Organization > Notifications and add an endpoint with its URL, an optional description, and the categories to send.

Prodgator shows the endpoint's signing secret () once. Store it; you need it to verify deliveries.

Payload

{
  "type": "notification.pipeline_failure",
  "timestamp": "2026-09-28T12:00:00.000Z",
  "data": {
    "id": "...",
    "orgId": "...",
    "category": "pipelineFailure",
    "type": "pipeline_failure",
    "severity": "critical",
    "title": "...",
    "message": "...",
    "url": "https://app.prodgator.io/app/...",
    "sourceType": "pipeline_run",
    "sourceId": "...",
    "createdAt": "...",
    "locale": "en",
    "i18n": {
      "titleKey": "pipelineFailed.title",
      "messageKey": "pipelineFailed.message",
      "params": { "workflow": "...", "repo": "...", "branch": "..." }
    }
  }
}

Language

and are written in the organization's Default language (see Organizations), or English when it has none. names that language as a tag such as , or . Everything else (, , , ids, ) stays the same in every language, so match on those, not on the text.

When Prodgator writes a notification from a template, carries the template keys and the values that fill them, so you can show the text in another language yourself. The values in can contain text people wrote, such as a reason or a name, so escape them before you show them. is when the message is someone's own words (a provider's alert title, a reason someone typed), which are never translated. Notifications without a template have no field.

and were added in October 2026. Both are additive: a receiver that ignores unknown fields keeps working.

Send test posts to the endpoint. Its has , a in the organization's default language, and .

Verifying the signature

Each request carries three headers:

HeaderValue
Unique message ID
Unix time in seconds
One or more space-separated values

To verify:

  1. Take the secret, drop the prefix and base64-decode the rest. That is the HMAC key.
  2. Compute HMAC-SHA256 over and base64-encode it.
  3. Accept the request if it matches any value, and the timestamp is within 5 minutes of now.

This is the Standard Webhooks scheme, so their libraries work too.

Rotating and failures

  • Rotate secret creates a new secret. For the next 24 hours each delivery is signed with both the old and new secret, so you can switch without dropping requests.
  • The delivery log shows recent attempts with their HTTP status.
  • Prodgator disables an endpoint after 10 failed deliveries in a row, if it returns , or if its host resolves to a private or blocked address. It then notifies your organization.

Sur cette page