Set up webhook notifications for your organization.
:::info Configure webhooks to subscribe to real-time updates for your pentests.
:::
With our API-based webhooks, you can set up an integration between your app and the Cobalt platform to get notifications for pentest events. We’ll send you updates for each event to your URL through an HTTP POST request.
When you work with an API, you can become aware of new data in the following ways:
Before You Start
Before you start creating webhooks, complete the configuration in your app.
Read our Best Practices for more information.
When you set up a webhook, you can select events to which you want to subscribe:
| Pentest | Finding |
|---|---|
| Pentest created \nPentest state updated | • Finding deleted \n• Finding published \n• Finding state updated \n• Finding updated |
For security reasons, we only post essential details about webhook events, such as their ID and type. To retrieve more information about the event, use the Cobalt API.
:::info Note
For webhooks that you created before June 2023, you get updates forall events. You can adjust the configuration of your existing webhooks. Select the three-dot iconunderActions, selectEdit Webhook, select webhook events in the overlay, and then selectSaveto confirm.
:::
Let’s configure webhooks in the Cobalt app.
To create a webhook:
Now you can manage the webhooks that you created.
You can check the status of your webhooks on the Webhooks page. The following icons indicate that there is a problem with your webhook:
Find solutions for common troubleshooting problems in the table below:
| Problem | Solution |
|---|---|
| You can’t create a webhook because the name or URL already exists. | Enter a unique name and URL for your webhook. |
| You can’t create a webhook because the validation fails.You don’t get webhook notifications to your URL.You can’t activate a webhook that we or you deactivated earlier. | We failed to validate your webhook. Check the following: \n• The URL is valid and can accept requests. \n• If you’re using a webhook secret to validate API requests from Cobalt, make sure that it’s valid. Refresh the secret or generate a new one if needed. |
| You can’t delete a webhook. | • Try again. \n• Contact your Customer Success Manager (CSM) or support@cobalt.io for assistance. |