Reference1 min read

Outbound webhook reference

Delivery, signing, retry, timeout, and receiver requirements for incident webhooks.

OpsKnight sends JSON over POST by default. Every request includes Content-Type: application/json, a user agent, and a stable X-OpsKnight-Delivery-Id that receivers should store for idempotent processing.

When a signing secret is configured, verify the lowercase hexadecimal HMAC SHA-256 in X-OpsKnight-Signature. The signed value is the exact X-OpsKnight-Timestamp, a period, and the unmodified request body. Reject stale timestamps before comparing signatures with a constant-time operation.

The default attempt timeout is 10 seconds and the default maximum is three attempts. Retryable HTTP responses and network failures use backoff; Retry-After is honored when present. A receiver response body is limited to 64 KiB. Destinations are checked against outbound-network restrictions before every attempt, so loopback, link-local, private, or otherwise restricted targets are rejected unless the deployment's network policy explicitly supports them.

Last updated for v2.0.0

Edit this page on GitHub