Documentation
Webhooks
A signed JSON POST for critical alerts.
When
A webhook is sent for critical alerts, once per event type and server per hour, alongside the alert email for that event. Lower severities go to the daily digest, not the webhook. Configure the URL and a secret in alert settings (plan-gated).
Request
- Method
- POST, JSON body, 10-second timeout; a response below 300 counts as delivered
- X-SecAI-Event
- The event type
- X-SecAI-Signature
- sha256=<HMAC-SHA256 of the raw body with your secret>, when a secret is set
Body
{
"event_type": "...",
"title": "...",
"server": "hostname",
"server_ip": "...",
"severity": "critical",
"severity_rationale": "...",
"detail": "...",
"attackers": [{"ip": "...", "country": "...", "blocked": true}],
"blocked_ips": ["..."],
"actions": [...],
"recommended_action": "...",
"incident_url": "https://secai.techsteps.ae/incidents/<id>",
"timestamp": "2026-09-20T12:00:00",
"dashboard_url": "https://secai.techsteps.ae"
}Verify
Compute HMAC-SHA256 over the exact request body with your secret and compare it, constant-time, to the value after sha256= in X-SecAI-Signature.
Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.