Register a webhook
Registers a public HTTPS endpoint for one event type. Your service receives previous and current values and decides how to respond. Creating a webhook does not disable a default hook.
The response includes a signing secret once. Store it in your service and verify deliveries as described in Webhook events. Destinations on private, loopback, link-local, or metadata-service addresses are rejected, including after DNS resolution. Redirects are not followed.
Authorizations
API key from your organization. Supply the value directly, without a Bearer prefix.
Body
Response
Created.
Built-in hook IDs are triage, remediation, and verification. Custom webhook IDs are opaque.
1vulnerability.status_changed, vulnerability.assignee_changed Webhook destination. Null for a built-in hook.
Signing secret returned only when the hook is created. Store it in your receiving service.