Receive Notifications
Receive Notifications
In this guide, we will set up a webhook to receive notifications from the Hyperion API.Overview
Webhooks provide a way to receive real-time notifications when activities occur in the Hyperion platform. Instead of polling the API for changes, you can configure a webhook endpoint that Hyperion will call whenever relevant events happen.
Webhooks can notify you about activities such as event creation, monitorable updates, a member added to your partner account, or monitorable incident actions from ADT operators (monitorable-incident:create and monitorable-incident:action:create). See Monitorable Incidents for the mapped action names.
Getting Started
Before creating a webhook, you need:
- An application with the
webhook:writescope. If you haven't created an application yet, see the Create Application guide to get started. - A publicly accessible HTTPS endpoint that can receive webhook notifications.
Once you have your application credentials, use the Set Access Token button in the navbar to configure your access token for making API requests.
Create a Webhook
To create a webhook, send a POST request to the /webhooks endpoint with your webhook configuration:
Response
Upon successful creation, you'll receive a response containing the webhook details:
{
"id": "550e8400-e29b-41d4-a716-446655440000",
"partnerId": "550e8400-e29b-41d4-a716-446655440001",
"url": "https://example.com/webhooks/hyperion",
"activityTypes": ["event:create", "monitorable:create"],
"enabled": true,
"createdAt": "2024-01-15T10:30:00Z",
"updatedAt": "2024-01-15T10:30:00Z"
}
Webhook Payload
When an event occurs that matches your webhook's activityTypes, Hyperion will send a POST request to your webhook URL with a JSON payload containing the activity details. The data field contains an object snapshot of the entity at the time of the activity:
Webhook activity
Example payload
event:create
1{2 "id": "550e8400-e29b-41d4-a716-446655440000",3 "partnerId": "550e8400-e29b-41d4-a716-446655440001",4 "entityId": "550e8400-e29b-41d4-a716-446655440002",5 "entityType": "EVENT",6 "activityType": "event:create",7 "scope": "event:read",8 "data": {9 "id": "550e8400-e29b-41d4-a716-446655440002",10 "externalId": "ext-event-12345",11 "partnerId": "550e8400-e29b-41d4-a716-446655440001",12 "monitorableId": "550e8400-e29b-41d4-a716-446655440003",13 "systemStatus": "ACTIVE",14 "createdAt": "2024-01-15T10:30:00Z",15 "updatedAt": "2024-01-20T14:45:00Z"16 },17 "createdAt": "2024-01-15T10:30:00Z"18}
Set an access token using the Set access token button in the navbar to send test webhooks.
Verifying Webhook Signatures
Each webhook request includes three signature headers following RFC 9421 (HTTP Message Signatures):
Signature-Input: Contains the signing key ID and creation timestamp, e.g.,sig=("@content");created=1618884473;keyid="<key-id>"Signature: Contains the base64-encoded signature wrapped in colons, e.g.,sig=:<base64-signature>:Signature-Agent: The fully qualified JWKS URL for fetching verification keys
Parse the label and keyid from the Signature-Input header, extract the label and signature from the Signature header, confirm the labels match, fetch the matching public key from the JWKS URL in the Signature-Agent header, and verify the signature against the raw request body using the algorithm specified in the key's alg field. The label (e.g., sig) must match between both headers -- always parse it dynamically.
For a detailed verification walkthrough with code examples, see the Webhooks concept page.
Conclusion
You've successfully created a webhook to receive real-time notifications from the Hyperion platform. Your webhook endpoint will now be called whenever events matching your configured notification types occur.
Learn More
Related Concepts
- Webhooks - Deep dive into webhook configuration and payloads
- Events - Activities that trigger webhook notifications
- Monitorable Incidents - Learn how to subscribe to monitorable incidents and operator actions
- Monitorables - Entities that generate events
API Reference
- Create Webhook - Register a new webhook
- Get Webhook - Retrieve webhook details
- List Webhooks - List all webhooks
- Update Webhook - Modify webhook configuration
- Delete Webhook - Remove a webhook