Webhooks are inbound only. CloudThinker does not POST events out to your endpoints. To send results outward, use notifications, Slack, or Microsoft Teams.
Prerequisites
- An Admin workspace role to create or change a webhook
- An external system that can send HTTPS POST requests with a JSON body
Two kinds of webhook
To start an agent from an HTTP call, add a webhook trigger to an Automation. The standalone Conversation webhook is gone from the app. Existing Conversation webhooks keep working.
How it works
- CloudThinker issues a unique URL containing the webhook token, plus a secret shown once.
- Your system POSTs a JSON body to that URL.
- CloudThinker authenticates the request, records the event, and returns 202 Accepted.
- A worker checks the hourly rate limit, dispatches the payload, and writes the final status.
Add a webhook trigger to an Automation
1
Open the Automation
Open an Automation and open its trigger menu.
2
Add a Webhook trigger
Select Webhook: “When an HTTP call arrives at a URL we issue.” Save the trigger.
3
Copy the URL and secret
The dialog shows the Webhook URL, the Secret, and a Test command.Success state: the trigger card shows the webhook, and each call appears in its delivery list.
Authorization: Bearer header. The URL answers 401 without it.
Resolve webhooks
A Resolve webhook opens an incident from an alert. Automatic RCA is on by default with a minimum severity of Medium. Create one from webhook integrations. The wizard has three steps: Basic Info, Configure, and Advanced.Request body
For a Resolve webhook, put every custom field inside
metadata. An Automation receives the whole body as its trigger payload.success, request_id, and — depending on the action type — conversation_id, incident_id, rca_run_id, and signal_id.
Authentication
An Automation webhook trigger always uses Bearer auth. For a Resolve webhook, choose one auth mode. CloudThinker verifies each incoming request before it accepts the payload.
The header name is configurable for HMAC and API key. Sign the raw request body with HMAC-SHA256 and send
sha256=<hex digest>:
Limits
A request over the hourly limit still gets 202, but the worker drops it and records
rate_limited. Above 10 times the limit, the endpoint answers 429 and records nothing.
Review deliveries
An Automation webhook trigger lists its deliveries on the trigger card. Each delivery has one of four statuses: Accepted, Processed, Failed, or Rate limited. CloudThinker never shows stored request headers or bodies, and keeps them internally for 90 days. To stop a webhook trigger, turn it Off on the trigger card. A call to a disabled trigger fails and does not start a run.Troubleshooting
401 or 403 on every request
401 or 403 on every request
The auth mode does not match what you send. Check the header name and confirm you are signing with the webhook’s own secret. An Automation webhook trigger accepts only
Authorization: Bearer <secret>.Signature mismatch
Signature mismatch
Sign the exact raw body bytes, before any reformatting, and send the digest as
sha256=<hex>. Re-serializing JSON changes the bytes and breaks the signature.429 responses
429 responses
The webhook is more than 10 times over its hourly rate limit. Slow the sender down. A smaller excess returns 202 and shows as Rate limited in the deliveries.
413 or a rejected large payload
413 or a rejected large payload
The body is over the 1 MB cap. Send a reference instead of the full document.
Related
Resolve Webhook Integrations
Route alerts from monitoring platforms into incidents
Automations
Run an agent on a schedule, a webhook, or a repository event
Notifications
Deliver CloudThinker results to email, Slack, and Teams