Outbound webhooks
Send organization-wide notifications to your own HTTPS endpoint, verify the signature, and rotate the secret.
Availability
Who can use this: Org admin only. See Roles.
Outbound webhooks
On the Business and Enterprise plans, Org admins can have Prodgator POST organization-wide notifications to their own HTTPS endpoints. Open Organization > Notifications and add an endpoint with its URL, an optional description, and the categories to send.
Prodgator shows the endpoint's signing secret () once. Store it; you need it to verify deliveries.
Payload
{
"type": "notification.pipeline_failure",
"timestamp": "2026-09-28T12:00:00.000Z",
"data": {
"id": "...",
"orgId": "...",
"category": "pipelineFailure",
"type": "pipeline_failure",
"severity": "critical",
"title": "...",
"message": "...",
"url": "https://app.prodgator.io/app/...",
"sourceType": "pipeline_run",
"sourceId": "...",
"createdAt": "...",
"locale": "en",
"i18n": {
"titleKey": "pipelineFailed.title",
"messageKey": "pipelineFailed.message",
"params": { "workflow": "...", "repo": "...", "branch": "..." }
}
}
}Language
and are written in the organization's Default language (see Organizations), or English when it has none. names that language as a tag such as , or . Everything else (, , , ids, ) stays the same in every language, so match on those, not on the text.
When Prodgator writes a notification from a template, carries the template keys and the values that fill them, so you can show the text in another language yourself. The values in can contain text people wrote, such as a reason or a name, so escape them before you show them. is when the message is someone's own words (a provider's alert title, a reason someone typed), which are never translated. Notifications without a template have no field.
and were added in October 2026. Both are additive: a receiver that ignores unknown fields keeps working.
Send test posts to the endpoint. Its has , a in the organization's default language, and .
Verifying the signature
Each request carries three headers:
| Header | Value |
|---|---|
| Unique message ID | |
| Unix time in seconds | |
| One or more space-separated values |
To verify:
- Take the secret, drop the prefix and base64-decode the rest. That is the HMAC key.
- Compute HMAC-SHA256 over and base64-encode it.
- Accept the request if it matches any value, and the timestamp is within 5 minutes of now.
This is the Standard Webhooks scheme, so their libraries work too.
Rotating and failures
- Rotate secret creates a new secret. For the next 24 hours each delivery is signed with both the old and new secret, so you can switch without dropping requests.
- The delivery log shows recent attempts with their HTTP status.
- Prodgator disables an endpoint after 10 failed deliveries in a row, if it returns , or if its host resolves to a private or blocked address. It then notifies your organization.