Webhooks
Standard-Webhooks-signed events pushed to your endpoints, with retries and per-attempt logs.
Outbound webhooks push events to your own HTTPS endpoints instead of you polling for them: monitor status changes, incident declarations, and alert events.
Subscribing
Manage endpoints under Settings → API Keys in the dashboard or via the
API (/v1/webhook-endpoints). Each endpoint gets a whsec_… secret and a
subscription to the event types you choose. Webhook management requires the
Pro plan; deliveries don't count against your API quota.
Verifying deliveries
Every delivery is signed with
Standard Webhooks headers
(webhook-id, webhook-timestamp, webhook-signature). Verify with the
SDK:
import { verifyWebhook } from "@uptimely/sdk/webhooks";
const result = verifyWebhook({
rawBody, // the EXACT raw request bytes
headers: req.headers, // webhook-id / -timestamp / -signature
secret: process.env.UPTIMELY_WEBHOOK_SECRET, // whsec_…
});
if (!result.valid) return unauthorized();Verify over the raw request bytes — any re-serialization breaks the signature.
Delivery behavior
- Failed deliveries are retried with backoff.
- Every attempt is logged and visible per endpoint, with replay for failed deliveries.
- Answer quickly with a 2xx and process async; slow endpoints get timed out and retried.