Alerts: email, Slack, Discord, Teams and webhooks
Where Webforta sends alerts and how to verify signed webhooks.
Alerts go to email recipients and to chat or webhook channels (Alerts & incidents). Each destination chooses its own categories: downtime, recovery, certificate expiry, DNS, header and content changes, blocklist warnings, new high-severity findings and domain expiry. The monthly report goes to email only.
Slack, Discord and Microsoft Teams
- Slack: create an app at api.slack.com/apps, enable Incoming Webhooks, add a webhook to the channel and paste its https://hooks.slack.com/... URL.
- Discord: Channel settings > Integrations > Webhooks > New webhook > Copy webhook URL. Alerts never mention @everyone or roles.
- Microsoft Teams: in the channel, choose Workflows > "Post to a channel when a webhook request is received", finish the steps and paste the URL.
- Use Send test to confirm delivery. The last delivery result is shown on each channel; webhook URLs are stored encrypted and never shown again.
Signed webhooks
A webhook channel POSTs JSON to your https endpoint: {"id", "type", "subject", "text", "sentAt"}. Each request carries Webforta-Event, Webforta-Delivery (unique per alert, use it to de-duplicate retries) and Webforta-Signature headers. Verify the signature before trusting the body:
Webforta-Signature: t=1760000000,v1=5257a869...
expected = HMAC_SHA256(signing_secret, t + "." + raw_request_body) // hex
accept if expected == v1 (constant-time compare) and t is within 5 minutes of nowThe signing secret is shown when you create the channel and under Show signing secret; Rotate secret replaces it. Webforta does not follow redirects, retries temporary failures (timeouts, HTTP 429 and 5xx) a few times, and does not retry other 4xx answers.