Skip to content

Receive incident webhooks

Create a Webhook notification channel in a group and enter the public receiver URL. Assign that group to checks. Pingstack POSTs JSON when a check alerts through this channel.

Your receiver must be publicly reachable; private/internal addresses are blocked. Use HTTPS and a destination you control. Avoid exposing receiver credentials in logs or source code.

{
"alert": "Human-readable alert text",
"check": {
"name": "Public website",
"status": "down"
},
"incident": {
"started_at": "2026-01-01T12:00:00Z",
"resolved_at": null,
"cause": "Human-readable cause"
}
}
Field Meaning
alert Display text; do not parse it as a stable event identifier
check.name Check name; not a unique machine identifier
check.status Current check status at payload construction
incident.started_at ISO 8601 incident start
incident.resolved_at ISO 8601 recovery time or null while unresolved
incident.cause Incident explanation; treat as display text

Recovery messages use the incident’s resolution time. This payload is different from the public API’s redacted incident resource: webhooks include the cause, while API incident reads do not.

Return a successful 20x HTTP response. Other responses produce delivery failure. Make processing tolerant of repeats; do not assume exactly-once delivery, signed events, a delivery identifier or a guaranteed retry cadence. These are not fields or guarantees of this webhook interface.

The channel form does not expose a signing secret or custom headers. Protect sensitive downstream actions independently; a received JSON body should not alone authorize a destructive action.

Inspect notification history after setup or a failed delivery.