Alerts: email, Slack, Discord, Teams and webhooks

Where Webforta sends alerts and how to verify signed webhooks.

Alerts go to email recipients and to chat or webhook channels (Alerts & incidents). Each destination chooses its own categories: downtime, recovery, certificate expiry, DNS, header and content changes, blocklist warnings, new high-severity findings and domain expiry. The monthly report goes to email only.

Slack, Discord and Microsoft Teams

  • Slack: create an app at api.slack.com/apps, enable Incoming Webhooks, add a webhook to the channel and paste its https://hooks.slack.com/... URL.
  • Discord: Channel settings > Integrations > Webhooks > New webhook > Copy webhook URL. Alerts never mention @everyone or roles.
  • Microsoft Teams: in the channel, choose Workflows > "Post to a channel when a webhook request is received", finish the steps and paste the URL.
  • Use Send test to confirm delivery. The last delivery result is shown on each channel; webhook URLs are stored encrypted and never shown again.

Signed webhooks

A webhook channel POSTs JSON to your https endpoint: {"id", "type", "subject", "text", "sentAt"}. Each request carries Webforta-Event, Webforta-Delivery (unique per alert, use it to de-duplicate retries) and Webforta-Signature headers. Verify the signature before trusting the body:

Webforta-Signature: t=1760000000,v1=5257a869...

expected = HMAC_SHA256(signing_secret, t + "." + raw_request_body)  // hex
accept if expected == v1 (constant-time compare) and t is within 5 minutes of now

The signing secret is shown when you create the channel and under Show signing secret; Rotate secret replaces it. Webforta does not follow redirects, retries temporary failures (timeouts, HTTP 429 and 5xx) a few times, and does not retry other 4xx answers.