Create a notification target
const url = 'http://localhost:3000/api/v1/notification-targets';const options = { method: 'POST', headers: {'X-API-Key': '<X-API-Key>', 'Content-Type': 'application/json'}, body: '{"name":"Ops on-call email","channel":"EMAIL","email":"ops@example.com","url":"https://hooks.example.com/services/T000/B000/XXXX","headers":{"X-Tenant-Token":"abc123"},"secret":"example","enabled":true}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url http://localhost:3000/api/v1/notification-targets \ --header 'Content-Type: application/json' \ --header 'X-API-Key: <X-API-Key>' \ --data '{ "name": "Ops on-call email", "channel": "EMAIL", "email": "ops@example.com", "url": "https://hooks.example.com/services/T000/B000/XXXX", "headers": { "X-Tenant-Token": "abc123" }, "secret": "example", "enabled": true }'A WEBHOOK target is assigned an HMAC-SHA256 signing secret when none is supplied. That secret is returned in THIS response only and is never readable again.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”object
Human-readable target name
Example
Ops on-call emailDelivery transport
Recipient address. Required when channel is EMAIL.
Example
ops@example.comEndpoint to POST to. Required when channel is WEBHOOK. Must be a public http(s) URL — private, loopback, link-local and in-cluster addresses are rejected to prevent SSRF.
Example
https://hooks.example.com/services/T000/B000/XXXXExtra headers sent on every webhook delivery. WEBHOOK only.
object
Example
{ "X-Tenant-Token": "abc123"}HMAC-SHA256 key used to sign webhook deliveries (X-Webhook-Signature). WEBHOOK only. Generated automatically when omitted — it is returned once on create and never again.
Whether the target receives deliveries
Responses
Section titled “Responses”object
EMAIL targets only
object
WEBHOOK targets only
object
WEBHOOK targets only
object
Whether webhook deliveries to this target are signed
HMAC-SHA256 signing key for webhook deliveries. Shown once, on creation, and never returned again. Store it in the receiving system to verify X-Webhook-Signature.
object
Example
{ "name": "Ops on-call email", "channel": "EMAIL"}Missing channel-specific field, or a webhook URL pointing at a private, loopback, link-local or in-cluster address