Skip to main content
POST
Register a webhook

Authorizations

x-api-key
string
header
required

API key from your organization. Supply the value directly, without a Bearer prefix.

Body

application/json
event
enum<string>
required
Available options:
vulnerability.status_changed,
vulnerability.assignee_changed
url
string<uri>
required

Public HTTPS endpoint that receives events.

Pattern: ^https://
enabled
boolean
default:true

Response

Created.

id
string
required

Built-in hook IDs are triage, remediation, and verification. Custom webhook IDs are opaque.

Minimum string length: 1
event
enum<string>
required
Available options:
vulnerability.status_changed,
vulnerability.assignee_changed
url
string<uri> | null
required

Webhook destination. Null for a built-in hook.

enabled
boolean
required
builtIn
boolean
required
createdAt
string<date-time>
required
updatedAt
string<date-time>
required
secret
string
required

Signing secret returned only when the hook is created. Store it in your receiving service.