Skip to content

Allow website probes through your firewall

Website probes send verification headers so you can distinguish your Pingstack requests in a firewall or WAF:

Header Scope
X-Pingstack-Check-Token One check
X-Pingstack-Account-Token The account

Use the verification values shown in the signed-in check configuration. Operational credential access requires Editor or Admin. Do not use the token in a public status-page URL as a verification secret.

  1. Confirm the target and path you intend to monitor.
  2. Copy the appropriate verification value privately into your WAF rule.
  3. Limit the exception to the necessary hostname/path and request behavior.
  4. Confirm subsequent probe results reach the endpoint and return the expected code.

Treat these values as credentials. Do not publish them in docs, logs exposed to customers or source control. A User-Agent identifies a convention, not an authenticated caller; it should not be the sole basis for bypassing protection.

A WAF allowance does not make an internal address monitorable. Pingstack requires public destinations, including redirect destinations.