Documentation

Webhooks

A signed JSON POST for critical alerts.

When

A webhook is sent for critical alerts, once per event type and server per hour, alongside the alert email for that event. Lower severities go to the daily digest, not the webhook. Configure the URL and a secret in alert settings (plan-gated).

Request

Method
POST, JSON body, 10-second timeout; a response below 300 counts as delivered
X-SecAI-Event
The event type
X-SecAI-Signature
sha256=<HMAC-SHA256 of the raw body with your secret>, when a secret is set

Body

{
  "event_type": "...",
  "title": "...",
  "server": "hostname",
  "server_ip": "...",
  "severity": "critical",
  "severity_rationale": "...",
  "detail": "...",
  "attackers": [{"ip": "...", "country": "...", "blocked": true}],
  "blocked_ips": ["..."],
  "actions": [...],
  "recommended_action": "...",
  "incident_url": "https://secai.techsteps.ae/incidents/<id>",
  "timestamp": "2026-09-20T12:00:00",
  "dashboard_url": "https://secai.techsteps.ae"
}

Verify

Compute HMAC-SHA256 over the exact request body with your secret and compare it, constant-time, to the value after sha256= in X-SecAI-Signature.

Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.

Trust Center