Receive incident webhooks
Create a Webhook notification channel in a group and enter the public receiver URL. Assign that group to checks. Pingstack POSTs JSON when a check alerts through this channel.
Your receiver must be publicly reachable; private/internal addresses are blocked. Use HTTPS and a destination you control. Avoid exposing receiver credentials in logs or source code.
Payload
Section titled “Payload”{ "alert": "Human-readable alert text", "check": { "name": "Public website", "status": "down" }, "incident": { "started_at": "2026-01-01T12:00:00Z", "resolved_at": null, "cause": "Human-readable cause" }}| Field | Meaning |
|---|---|
alert |
Display text; do not parse it as a stable event identifier |
check.name |
Check name; not a unique machine identifier |
check.status |
Current check status at payload construction |
incident.started_at |
ISO 8601 incident start |
incident.resolved_at |
ISO 8601 recovery time or null while unresolved |
incident.cause |
Incident explanation; treat as display text |
Recovery messages use the incident’s resolution time. This payload is different from the public API’s redacted incident resource: webhooks include the cause, while API incident reads do not.
Receiver behavior
Section titled “Receiver behavior”Return a successful 20x HTTP response. Other responses produce delivery
failure. Make processing tolerant of repeats; do not assume exactly-once
delivery, signed events, a delivery identifier or a guaranteed retry cadence.
These are not fields or guarantees of this webhook interface.
The channel form does not expose a signing secret or custom headers. Protect sensitive downstream actions independently; a received JSON body should not alone authorize a destructive action.
Inspect notification history after setup or a failed delivery.