Skip to content

Webhook deliveries

Vulnify POSTs these deliveries to your endpoint. They are not routes you call. The tables are generated from the webhooks section of https://api.vulnify.io/openapi.json. Signing, retries, and payload examples are on Webhooks.

Sent when a live decision is BLOCK, REVIEW, CRITICAL (CRITICAL can be combined with BLOCK or REVIEW). One delivery per endpoint. Sandbox events are not sent.

HMAC-SHA256. The key is the endpoint secret as UTF-8: the whole whsec_ value, prefix included, not base64-decoded. The signed message is the unix timestamp in seconds, a dot, and the raw body (`t.` + raw body). x-vulnify-signature is `t={unix seconds},v1={hex}`. Reject the delivery when abs(now - t) is greater than 300 seconds. The raw body is canonical JSON (object keys sorted). Verify those exact bytes.

OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook decision. Parameters.
NameInRequiredTypeDescription
Content-Typeheaderyesapplication/jsonJSON body.
User-AgentheaderyesVulnify-Webhooks/1.0Sender identity.
X-Vulnify-Signatureheaderyesstring (pattern ^t=[0-9]+,v1=[0-9a-f]{64}$)HMAC-SHA256. The key is the endpoint secret as UTF-8: the whole whsec_ value, prefix included, not base64-decoded. The signed message is the unix timestamp in seconds, a dot, and the raw body (`t.` + raw body). x-vulnify-signature is `t={unix seconds},v1={hex}`. Reject the delivery when abs(now - t) is greater than 300 seconds. The raw body is canonical JSON (object keys sorted). Verify those exact bytes.
X-Vulnify-Attemptheaderyesstring (pattern ^[1-9][0-9]*$)This attempt, starting at 1. The same delivery id is retried with a higher number.
X-Vulnify-EventheaderyesBLOCK | REVIEW | CRITICALPrimary event type. Same as body.type.
X-Vulnify-Deliveryheaderyesstring (uuid)Delivery id. Same as body.id.
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook decision. Request body.
FieldTypeRequiredDescription
idstring (uuid)yesDelivery id. The same value is sent on every retry. Dedupe on it.
typeBLOCK | REVIEW | CRITICALyesPrimary type. The first entry of types, and the X-Vulnify-Event header.
typesarray of BLOCK | REVIEW | CRITICAL (min items 1, unique)yesEvery decision type this event matched, in this order: BLOCK if the decision is BLOCK, REVIEW if it is REVIEW, CRITICAL if the risk level is CRITICAL. A delivery is one of those, or BLOCK plus CRITICAL, or REVIEW plus CRITICAL.
eventIdstring (uuid)yesSecurity event id. Same as data.id.
createdAtstring (date-time)yes
dataobjectyes
data.idstring (uuid)yesSecurity event id. Same as the envelope eventId.
data.agentstringyesAgent name.
data.actionREAD_DATA | WRITE_DATA | DELETE_DATA | EXPORT_DATA | SEND_EMAILyes
data.resourcestringyesResource name.
data.riskScoreinteger (0–100)yes
data.riskLevelLOW | MEDIUM | HIGH | CRITICALyes
data.decisionALLOW | REVIEW | BLOCKyesDecision recorded on the event. It does not change when a review is resolved.
data.finalDecisionALLOW | REVIEW | BLOCKyesEffective outcome at send time. REVIEW while a review is pending, ALLOW after approval, BLOCK after denial or expiry. Equals decision when the event has no review.
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook decision. Acknowledgement.
StatusMeaning
200Any 2xx acknowledges the delivery. 408, 429 and 5xx are retried. Any other 4xx stops retries.

Sent when a scan opens an anomaly (VOLUME_SPIKE, NEW_ACTION, NEW_EXTERNAL_DEST, RATE_SPIKE). One delivery per endpoint.

HMAC-SHA256. The key is the endpoint secret as UTF-8: the whole whsec_ value, prefix included, not base64-decoded. The signed message is the unix timestamp in seconds, a dot, and the raw body (`t.` + raw body). x-vulnify-signature is `t={unix seconds},v1={hex}`. Reject the delivery when abs(now - t) is greater than 300 seconds. The raw body is canonical JSON (object keys sorted). Verify those exact bytes.

OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook anomaly. Parameters.
NameInRequiredTypeDescription
Content-Typeheaderyesapplication/jsonJSON body.
User-AgentheaderyesVulnify-Webhooks/1.0Sender identity.
X-Vulnify-Signatureheaderyesstring (pattern ^t=[0-9]+,v1=[0-9a-f]{64}$)HMAC-SHA256. The key is the endpoint secret as UTF-8: the whole whsec_ value, prefix included, not base64-decoded. The signed message is the unix timestamp in seconds, a dot, and the raw body (`t.` + raw body). x-vulnify-signature is `t={unix seconds},v1={hex}`. Reject the delivery when abs(now - t) is greater than 300 seconds. The raw body is canonical JSON (object keys sorted). Verify those exact bytes.
X-Vulnify-Attemptheaderyesstring (pattern ^[1-9][0-9]*$)This attempt, starting at 1. The same delivery id is retried with a higher number.
X-Vulnify-EventheaderyesANOMALYPrimary event type. Same as body.type.
X-Vulnify-Deliveryheaderyesstring (uuid)Delivery id. Same as body.id.
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook anomaly. Request body.
FieldTypeRequiredDescription
idstring (uuid)yesDelivery id. The same value is sent on every retry. Dedupe on it.
typeANOMALYyesPrimary type. The first entry of types, and the X-Vulnify-Event header.
typesarray of ANOMALY (min items 1, max items 1)yes
eventIdstring (uuid)yesAnomaly id. Same as data.id.
createdAtstring (date-time)yes
dataobjectyes
data.idstring (uuid)yesAnomaly id. Same as the envelope eventId.
data.kindVOLUME_SPIKE | NEW_ACTION | NEW_EXTERNAL_DEST | RATE_SPIKEyes
data.severityLOW | MEDIUM | HIGH | CRITICALyes
data.messagestringyesEnglish fallback. Render messageCode and messageParams for other languages.
data.agentIdstring (uuid)yes
data.messageCodeanomaly.volume_spike | anomaly.new_action | anomaly.new_external_destination | anomaly.rate_spikeyes
data.messageParamsobjectyesParameters for messageCode. Values are strings, numbers, or null.
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook anomaly. Acknowledgement.
StatusMeaning
200Any 2xx acknowledges the delivery. 408, 429 and 5xx are retried. Any other 4xx stops retries.

Sent only when an administrator requests a test event. It is not a security decision.

HMAC-SHA256. The key is the endpoint secret as UTF-8: the whole whsec_ value, prefix included, not base64-decoded. The signed message is the unix timestamp in seconds, a dot, and the raw body (`t.` + raw body). x-vulnify-signature is `t={unix seconds},v1={hex}`. Reject the delivery when abs(now - t) is greater than 300 seconds. The raw body is canonical JSON (object keys sorted). Verify those exact bytes.

OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook test. Parameters.
NameInRequiredTypeDescription
Content-Typeheaderyesapplication/jsonJSON body.
User-AgentheaderyesVulnify-Webhooks/1.0Sender identity.
X-Vulnify-Signatureheaderyesstring (pattern ^t=[0-9]+,v1=[0-9a-f]{64}$)HMAC-SHA256. The key is the endpoint secret as UTF-8: the whole whsec_ value, prefix included, not base64-decoded. The signed message is the unix timestamp in seconds, a dot, and the raw body (`t.` + raw body). x-vulnify-signature is `t={unix seconds},v1={hex}`. Reject the delivery when abs(now - t) is greater than 300 seconds. The raw body is canonical JSON (object keys sorted). Verify those exact bytes.
X-Vulnify-Attemptheaderyesstring (pattern ^[1-9][0-9]*$)This attempt, starting at 1. The same delivery id is retried with a higher number.
X-Vulnify-EventheaderyesTESTPrimary event type. Same as body.type.
X-Vulnify-Deliveryheaderyesstring (uuid)Delivery id. Same as body.id.
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook test. Request body.
FieldTypeRequiredDescription
idstring (uuid)yesDelivery id. The same value is sent on every retry. Dedupe on it.
typeTESTyesPrimary type. The first entry of types, and the X-Vulnify-Event header.
typesarray of TEST (min items 1, max items 1)yes
eventIdstring (pattern ^test-[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$)yestest- followed by a UUID
createdAtstring (date-time)yes
dataobjectyes
data.messageTest event from Vulnifyyes
data.webhookIdstring (uuid)yesWebhook endpoint id.
data.organizationIdstring (uuid)yes
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json), webhook test. Acknowledgement.
StatusMeaning
200Any 2xx acknowledges the delivery. 408, 429 and 5xx are retried. Any other 4xx stops retries.