Webhooks

Install an https endpoint you control

A webhook channel posts a JSON body to your URL for each alert and signs it with a secret you copy once. Verify the signature before you trust the body.

1Add the channel

Integrations, Webhook: enter an https URL, pick the project scope and which alerts. The signing secret (whsec_...) is shown once: 'Copy the signing secret now. It will not be shown again.'

2Verify the signature

The header x-blipit-signature is the hex HMAC-SHA256 of the raw request body using your secret. Compare in constant time.

js
import { createHmac, timingSafeEqual } from "node:crypto";

export function verify(rawBody, header, secret) {
  const expected = createHmac("sha256", secret).update(rawBody).digest("hex");
  return header.length === expected.length && timingSafeEqual(Buffer.from(header), Buffer.from(expected));
}

3Read the body

Issue alerts look like this. type is new_issue, regression, security or test; security is present only for security alerts.

json
{
  "type": "new_issue",
  "project": { "id": 12, "name": "shop" },
  "issue": { "id": 981, "title": "TypeError: cart is undefined", "url": "https://app.blipit.io/issues/981", "level": "error", "event_count": 1 },
  "event": { "release": "2026.09.28", "environment": "production", "platform": "javascript" },
  "sent_at": "2026-09-28T09:15:00.000Z"
}

Good to know

  • Monitor changes post the same way with type monitor.down or monitor.up, and notices monitor.slow, monitor.fast and monitor.expiring.
  • Only https URLs on public addresses are accepted; redirects are not followed. Use the test button after saving to see a type: test delivery.
  • Answer 2xx quickly. A failed delivery shows as an error on the channel; Blipit does not queue it for later.

Stuck? Email support@blipit.io. Keys and the exact DSN for each project are under API keys in app.blipit.io.