Vulnify POSTs these deliveries to your endpoint. They are not routes you call. The tables are generated from the webhooks section of https://api.vulnify.io/openapi.json. Signing, retries, and payload examples are on Webhooks.
Sent when a live decision is BLOCK, REVIEW, CRITICAL (CRITICAL can be combined with BLOCK or REVIEW). One delivery per endpoint. Sandbox events are not sent.
HMAC-SHA256. The key is the endpoint secret as UTF-8: the whole whsec_ value, prefix included, not base64-decoded. The signed message is the unix timestamp in seconds, a dot, and the raw body (`t.` + raw body). x-vulnify-signature is `t={unix seconds},v1={hex}`. Reject the delivery when abs(now - t) is greater than 300 seconds. The raw body is canonical JSON (object keys sorted). Verify those exact bytes.
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook decision. Parameters.| Name | In | Required | Type | Description |
|---|
Content-Type | header | yes | application/json | JSON body. |
User-Agent | header | yes | Vulnify-Webhooks/1.0 | Sender identity. |
X-Vulnify-Signature | header | yes | string (pattern ^t=[0-9]+,v1=[0-9a-f]{64}$) | HMAC-SHA256. The key is the endpoint secret as UTF-8: the whole whsec_ value, prefix included, not base64-decoded. The signed message is the unix timestamp in seconds, a dot, and the raw body (`t.` + raw body). x-vulnify-signature is `t={unix seconds},v1={hex}`. Reject the delivery when abs(now - t) is greater than 300 seconds. The raw body is canonical JSON (object keys sorted). Verify those exact bytes. |
X-Vulnify-Attempt | header | yes | string (pattern ^[1-9][0-9]*$) | This attempt, starting at 1. The same delivery id is retried with a higher number. |
X-Vulnify-Event | header | yes | BLOCK | REVIEW | CRITICAL | Primary event type. Same as body.type. |
X-Vulnify-Delivery | header | yes | string (uuid) | Delivery id. Same as body.id. |
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook decision. Request body.| Field | Type | Required | Description |
|---|
id | string (uuid) | yes | Delivery id. The same value is sent on every retry. Dedupe on it. |
type | BLOCK | REVIEW | CRITICAL | yes | Primary type. The first entry of types, and the X-Vulnify-Event header. |
types | array of BLOCK | REVIEW | CRITICAL (min items 1, unique) | yes | Every decision type this event matched, in this order: BLOCK if the decision is BLOCK, REVIEW if it is REVIEW, CRITICAL if the risk level is CRITICAL. A delivery is one of those, or BLOCK plus CRITICAL, or REVIEW plus CRITICAL. |
eventId | string (uuid) | yes | Security event id. Same as data.id. |
createdAt | string (date-time) | yes | |
data | object | yes | |
data.id | string (uuid) | yes | Security event id. Same as the envelope eventId. |
data.agent | string | yes | Agent name. |
data.action | READ_DATA | WRITE_DATA | DELETE_DATA | EXPORT_DATA | SEND_EMAIL | yes | |
data.resource | string | yes | Resource name. |
data.riskScore | integer (0–100) | yes | |
data.riskLevel | LOW | MEDIUM | HIGH | CRITICAL | yes | |
data.decision | ALLOW | REVIEW | BLOCK | yes | Decision recorded on the event. It does not change when a review is resolved. |
data.finalDecision | ALLOW | REVIEW | BLOCK | yes | Effective outcome at send time. REVIEW while a review is pending, ALLOW after approval, BLOCK after denial or expiry. Equals decision when the event has no review. |
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook decision. Acknowledgement.| Status | Meaning |
|---|
200 | Any 2xx acknowledges the delivery. 408, 429 and 5xx are retried. Any other 4xx stops retries. |
Sent when a scan opens an anomaly (VOLUME_SPIKE, NEW_ACTION, NEW_EXTERNAL_DEST, RATE_SPIKE). One delivery per endpoint.
HMAC-SHA256. The key is the endpoint secret as UTF-8: the whole whsec_ value, prefix included, not base64-decoded. The signed message is the unix timestamp in seconds, a dot, and the raw body (`t.` + raw body). x-vulnify-signature is `t={unix seconds},v1={hex}`. Reject the delivery when abs(now - t) is greater than 300 seconds. The raw body is canonical JSON (object keys sorted). Verify those exact bytes.
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook anomaly. Parameters.| Name | In | Required | Type | Description |
|---|
Content-Type | header | yes | application/json | JSON body. |
User-Agent | header | yes | Vulnify-Webhooks/1.0 | Sender identity. |
X-Vulnify-Signature | header | yes | string (pattern ^t=[0-9]+,v1=[0-9a-f]{64}$) | HMAC-SHA256. The key is the endpoint secret as UTF-8: the whole whsec_ value, prefix included, not base64-decoded. The signed message is the unix timestamp in seconds, a dot, and the raw body (`t.` + raw body). x-vulnify-signature is `t={unix seconds},v1={hex}`. Reject the delivery when abs(now - t) is greater than 300 seconds. The raw body is canonical JSON (object keys sorted). Verify those exact bytes. |
X-Vulnify-Attempt | header | yes | string (pattern ^[1-9][0-9]*$) | This attempt, starting at 1. The same delivery id is retried with a higher number. |
X-Vulnify-Event | header | yes | ANOMALY | Primary event type. Same as body.type. |
X-Vulnify-Delivery | header | yes | string (uuid) | Delivery id. Same as body.id. |
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook anomaly. Request body.| Field | Type | Required | Description |
|---|
id | string (uuid) | yes | Delivery id. The same value is sent on every retry. Dedupe on it. |
type | ANOMALY | yes | Primary type. The first entry of types, and the X-Vulnify-Event header. |
types | array of ANOMALY (min items 1, max items 1) | yes | |
eventId | string (uuid) | yes | Anomaly id. Same as data.id. |
createdAt | string (date-time) | yes | |
data | object | yes | |
data.id | string (uuid) | yes | Anomaly id. Same as the envelope eventId. |
data.kind | VOLUME_SPIKE | NEW_ACTION | NEW_EXTERNAL_DEST | RATE_SPIKE | yes | |
data.severity | LOW | MEDIUM | HIGH | CRITICAL | yes | |
data.message | string | yes | English fallback. Render messageCode and messageParams for other languages. |
data.agentId | string (uuid) | yes | |
data.messageCode | anomaly.volume_spike | anomaly.new_action | anomaly.new_external_destination | anomaly.rate_spike | yes | |
data.messageParams | object | yes | Parameters for messageCode. Values are strings, numbers, or null. |
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook anomaly. Acknowledgement.| Status | Meaning |
|---|
200 | Any 2xx acknowledges the delivery. 408, 429 and 5xx are retried. Any other 4xx stops retries. |
Sent only when an administrator requests a test event. It is not a security decision.
HMAC-SHA256. The key is the endpoint secret as UTF-8: the whole whsec_ value, prefix included, not base64-decoded. The signed message is the unix timestamp in seconds, a dot, and the raw body (`t.` + raw body). x-vulnify-signature is `t={unix seconds},v1={hex}`. Reject the delivery when abs(now - t) is greater than 300 seconds. The raw body is canonical JSON (object keys sorted). Verify those exact bytes.
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook test. Parameters.| Name | In | Required | Type | Description |
|---|
Content-Type | header | yes | application/json | JSON body. |
User-Agent | header | yes | Vulnify-Webhooks/1.0 | Sender identity. |
X-Vulnify-Signature | header | yes | string (pattern ^t=[0-9]+,v1=[0-9a-f]{64}$) | HMAC-SHA256. The key is the endpoint secret as UTF-8: the whole whsec_ value, prefix included, not base64-decoded. The signed message is the unix timestamp in seconds, a dot, and the raw body (`t.` + raw body). x-vulnify-signature is `t={unix seconds},v1={hex}`. Reject the delivery when abs(now - t) is greater than 300 seconds. The raw body is canonical JSON (object keys sorted). Verify those exact bytes. |
X-Vulnify-Attempt | header | yes | string (pattern ^[1-9][0-9]*$) | This attempt, starting at 1. The same delivery id is retried with a higher number. |
X-Vulnify-Event | header | yes | TEST | Primary event type. Same as body.type. |
X-Vulnify-Delivery | header | yes | string (uuid) | Delivery id. Same as body.id. |
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook test. Request body.| Field | Type | Required | Description |
|---|
id | string (uuid) | yes | Delivery id. The same value is sent on every retry. Dedupe on it. |
type | TEST | yes | Primary type. The first entry of types, and the X-Vulnify-Event header. |
types | array of TEST (min items 1, max items 1) | yes | |
eventId | string (pattern ^test-[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$) | yes | test- followed by a UUID |
createdAt | string (date-time) | yes | |
data | object | yes | |
data.message | Test event from Vulnify | yes | |
data.webhookId | string (uuid) | yes | Webhook endpoint id. |
data.organizationId | string (uuid) | yes | |
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook test. Acknowledgement.| Status | Meaning |
|---|
200 | Any 2xx acknowledges the delivery. 408, 429 and 5xx are retried. Any other 4xx stops retries. |