Skip to main content
Webhook destinations send monitor alerts as JSON to any HTTP endpoint, so you can drive custom systems, automation platforms and internal tools. Webhooks are available on every plan, including Free. Every webhook is signed with a secret unique to that endpoint, so you can verify that a request genuinely came from UptimeIO.

Setting Up a Webhook

1

Open Destinations

Go to Destinations in the sidebar, click Add Destination, then choose Webhook.
2

Configure the Webhook

The URL must be publicly reachable. localhost and private IP ranges are rejected. Use HTTPS in production.
3

Configure Events

Select which events trigger this webhook. All six are enabled by default; at least one must stay enabled.
4

Copy your signing secret

Open the integration and reveal Signing secret (whsec_…). Store it in your receiving application — you need it to verify incoming requests.
5

Test

Use the Test button to verify connectivity.

Webhook Payload

Every UptimeIO webhook has the same body shape, regardless of which event fired:
incident.started_at can be null on recovery events. UptimeIO sends null rather than substituting the resolution time, so that a null is never mistaken for an incident that began the instant it ended. Treat started_at as optional.

Event types

New event types may be added in future. Ignore events you do not recognise rather than rejecting the request.

Headers

Every request includes:

Verifying the Signature

The signature is an HMAC-SHA256 over the string {timestamp}.{raw request body}, keyed with your endpoint’s signing secret, hex-encoded and prefixed with sha256=.
Compute the HMAC over the raw request body bytes, exactly as received. If you parse the JSON and re-serialize it before hashing, the signature will not match.
Also reject requests whose X-UptimeIO-Timestamp is far from your current clock (a few minutes’ tolerance is typical). This limits replay of a captured payload.

Rotating the secret

Open the destination and choose Rotate secret (API: POST /api/integrations/{instanceId}/rotate-secret, session token). The previous secret stops working immediately, so have your receiving application ready to switch: verification fails between rotation and deployment.

Custom Headers

Add authentication or custom metadata:
Custom headers cannot override Content-Type or any X-UptimeIO-* header; those are set by UptimeIO and take precedence.

Troubleshooting

Next Steps

Notification Setup

Assign webhooks directly to monitors

Events

Choose which events trigger notifications