Authdog
Log In

Log Streaming · Setup

Set up Webhooks

A webhook channel posts identity events to any HTTPS endpoint you operate.

One environment can have several channels, each with its own URL and triggers. This is not the Slack channel and not a SIEM drain. Those are separate channel types.

Add the channel

In the Authdog console:

  1. Select the project and environment.
  2. Open Notifications > Channels.
  3. Select Add Channel.
  4. Set Channel Name and Channel Type to Webhook.
  5. Paste an HTTPS URL into Webhook URL.
  6. Pick the triggers. A growth endpoint might take sign-ups only. A security endpoint might take failures and privilege changes. An empty event list drains every event.
  7. Save and send a test.

The URL is stored as a secret and shown redacted after save. Open the channel and copy Signing secret. It starts with whsec_. Rotate replaces it immediately, with no overlap period, so update the receiver before you send the next test.

Any 2xx response is success. Failures retry with backoff starting at 60 seconds, up to five attempts. A brief outage does not drop the event.

Verify the caller

Generic webhook deliveries include:

  • X-Authdog-Signature: t=<unix>, v1=<hex>
  • X-Authdog-Event-Type
  • X-Authdog-Delivery-Id

v1 is HMAC-SHA256 over the exact bytes of t + "." + rawBody, using the channel signing secret. Read the raw body before you parse JSON, reject stale timestamps, and compare digests in constant time. Store the delivery ID and treat the handler as idempotent. Retries can deliver the same event more than once.

The full check is in Events and webhooks.

Test it

  1. Send the channel's test delivery and confirm your endpoint recorded a 2xx.
  2. Trigger a real event you subscribed to, such as a sign-in in that environment.
  3. Confirm a channel with a narrow trigger list stays quiet for events you did not select.

Create the production channel in the production environment. Dev and prod do not share URLs or signing secrets.

Read To learn how to
Webhooks (JSON) The JSON body and how to verify it
Events and webhooks Signature fields, retries, and the event catalog
Notifications Channels versus email providers
Marketplace The listing for this integration