Skip to main content
A webhook destination receives each alert as a signed JSON POST. Signatures follow the Standard Webhooks scheme, so any Standard Webhooks library can verify them. To create one, see Alert destinations.

Request

CostGraph sends these headers with every request: Your endpoint must answer with a 2xx status within 10 seconds. A 429 or a 5xx is retried for up to 24 hours. Any other 4xx is treated as a rejection and isn’t retried.

Payload

Every alert has the same envelope. data.details carries the fields for the alert type.
The most common alert types and their details fields: When many critical anomalies open at once, CostGraph sends the first few and then one summary alert with an overflow_count of the rest.

Verify the signature

Each destination has its own signing secret, shown once when you create the destination. It starts with whsec_. To check a request:
  1. Strip whsec_ from the secret and base64-decode the rest to get the key.
  2. Build the signed content: {webhook-id}.{webhook-timestamp}.{raw body}.
  3. Compute an HMAC-SHA256 of the signed content with the key, and base64-encode it.
  4. Compare it with each v1, entry in webhook-signature, using a constant-time comparison.
  5. Reject the request if webhook-timestamp is more than five minutes from your clock.
Verify against the raw request body, before any JSON parsing.
Store webhook-id values you have processed and skip repeats, because a retry can deliver a message you already handled.

Change the secret

A signing secret stays the same when you edit the destination, including its URL. To get a new secret, delete the destination and create it again.