Skip to main content
A webhook channel on a certificate alert sends an HTTP POST request to your endpoint whenever the alert fires. Use a webhook to connect certificate alerts to your own systems or to services Infisical doesn’t support directly.

Add a webhook channel to an alert

1
Create an alert in your application, or edit an existing one.
2
Select Add Channel > Webhook and enter the URL of your endpoint. The URL must use HTTPS.
3
Optionally, enter a Signing Secret so your endpoint can verify the signature of each request.
4
Optionally, select Send test to send a test notification to the channel.
5
Select Continue, check the Review step, and select Create Alert.

Webhook event types

Each request is a CloudEvents JSON payload. The type and subject fields name the event:

Webhook payload format

data.items lists the certificates the alert fired for. Each item has the certificate’s ID, a title (its common name, or its first SAN or serial number when it has none), a one-line summary, a severity, and a list of display fields. To act on a certificate in code, read resource instead of fields: it holds the certificate’s typed values, with ISO 8601 dates and the raw revocation reason code. An expiration request can include several certificates, and data.alert.condition holds the alert’s lead time as you entered it, such as 30d or 2w. Issuance, renewal, and revocation requests include the one certificate the event was about.
Only alerts created in an application send this payload. Alerts created before certificate alerts moved to applications keep sending the older com.infisical.pki.certificate.* event types with a data.certificates list. If one endpoint receives both, check the type field to tell them apart.

Webhook signature verification

If you set a signing secret, each request carries an x-infisical-signature header:

Verify the signature

  1. Read the timestamp and the signature from the header
  2. Join the timestamp and the raw request body with a dot: {timestamp}.{raw-body}
  3. Compute the HMAC SHA256 of that string with your signing secret
  4. Compare the result with the signature from the header

What’s next?

Slack

Send alerts to a Slack channel.

PagerDuty

Create incidents in PagerDuty.

Certificate syncs

Push certificates to cloud destinations.

Certificates

View and manage certificates.