POST. Signatures
follow the Standard Webhooks scheme, so
any Standard Webhooks library can verify them. To create one, see
Alert destinations.
Request
CostGraph sends these headers with every request:
Your endpoint must answer with a
2xx status within 10 seconds. A 429 or a
5xx is retried for up to 24 hours. Any other 4xx is treated as a rejection
and isn’t retried.
Payload
Every alert has the same envelope.data.details carries the fields for the
alert type.
details fields:
When many critical anomalies open at once, CostGraph sends the first few and
then one summary alert with an
overflow_count of the rest.
Verify the signature
Each destination has its own signing secret, shown once when you create the destination. It starts withwhsec_. To check a request:
- Strip
whsec_from the secret and base64-decode the rest to get the key. - Build the signed content:
{webhook-id}.{webhook-timestamp}.{raw body}. - Compute an HMAC-SHA256 of the signed content with the key, and base64-encode it.
- Compare it with each
v1,entry inwebhook-signature, using a constant-time comparison. - Reject the request if
webhook-timestampis more than five minutes from your clock.
- Python
- Node.js
webhook-id values you have processed and skip repeats, because a retry
can deliver a message you already handled.