Automations, agents & monitors
Signed webhooks for monitor incidents
Incidents are most useful where your team already works. Webhooks deliver them to any HTTPS endpoint — signed so the receiver can trust them.
What it does
Each incident is sent as a JSON POST with the X-AdAce-Signature header in the form t=timestamp,v1=signature, where the signature is an HMAC-SHA256 made with your secret. The receiver recomputes it to verify the sender and integrity. Delivery is retried up to three times with increasing delays.
Webhook addresses must be HTTPS on a public host, without credentials in the URL; private and service IP addresses are refused and redirects are not followed.
Why it helps
- Integrate alerts with chat tools, on-call systems or CRMs.
- Verifiable authenticity of every message.
- Reliable delivery with retries.
How to set it up
- Prepare an HTTPS endpoint that verifies the signature.
- In the monitor settings, add the webhook URL and secret.
- Trigger a test or wait for the next incident and check your receiver.
Good to know
- Keep the webhook secret private; rotate it if exposed.
- Payloads contain incident details, not access tokens.



Try it on your own accounts
Create a workspace, connect Google or Meta in a couple of clicks and see your accounts clearly. Changes follow your approvals or the policy you configure.
Create your workspace