Skip to content

Create a notification target

POST
/api/v1/notification-targets
curl --request POST \
--url http://localhost:3000/api/v1/notification-targets \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <X-API-Key>' \
--data '{ "name": "Ops on-call email", "channel": "EMAIL", "email": "ops@example.com", "url": "https://hooks.example.com/services/T000/B000/XXXX", "headers": { "X-Tenant-Token": "abc123" }, "secret": "example", "enabled": true }'

A WEBHOOK target is assigned an HMAC-SHA256 signing secret when none is supplied. That secret is returned in THIS response only and is never readable again.

Media typeapplication/json
object
name
required

Human-readable target name

string
Example
Ops on-call email
channel
required

Delivery transport

string
Allowed values: EMAIL WEBHOOK
email

Recipient address. Required when channel is EMAIL.

string
Example
ops@example.com
url

Endpoint to POST to. Required when channel is WEBHOOK. Must be a public http(s) URL — private, loopback, link-local and in-cluster addresses are rejected to prevent SSRF.

string
Example
https://hooks.example.com/services/T000/B000/XXXX
headers

Extra headers sent on every webhook delivery. WEBHOOK only.

object
key
additional properties
string
Example
{
"X-Tenant-Token": "abc123"
}
secret

HMAC-SHA256 key used to sign webhook deliveries (X-Webhook-Signature). WEBHOOK only. Generated automatically when omitted — it is returned once on create and never again.

string
enabled

Whether the target receives deliveries

boolean
default: true
Media typeapplication/json
object
id
required
string format: uuid
name
required
string
channel
required
string
Allowed values: EMAIL WEBHOOK
email

EMAIL targets only

object
url

WEBHOOK targets only

object
headers

WEBHOOK targets only

object
key
additional properties
string
signed
required

Whether webhook deliveries to this target are signed

boolean
enabled
required
boolean
createdAt
required
string format: date-time
updatedAt
required
string format: date-time
secret

HMAC-SHA256 signing key for webhook deliveries. Shown once, on creation, and never returned again. Store it in the receiving system to verify X-Webhook-Signature.

object
Example
{
"name": "Ops on-call email",
"channel": "EMAIL"
}

Missing channel-specific field, or a webhook URL pointing at a private, loopback, link-local or in-cluster address