Prerequisites
- An HTTP or HTTPS endpoint that accepts
POSTrequests with a JSON body. - Any authentication the endpoint needs, applied on the receiving side.
Connect Webhook
1
Open the Applications tab
In the console sidebar, open Integrations and select the Applications tab.
2
Open Webhook
Select the Webhook card.
3
Enter a name and URL
Enter an Integration name, then enter the URL that should receive the payloads.
4
Choose events
Use the Event and Severity switches to control what OASM sends. See What notification integrations send.
5
Connect
Select Connect. OASM posts a welcome payload to confirm the endpoint is reachable.
Payload format
Each event is aPOST request with a JSON body:
Your endpoint should return a
2xx status. A non-2xx response is treated as a delivery failure and logged.
The payload shape is fixed. To attach custom headers or reshape the body, put a small adapter in front of your endpoint.
Test
Open the integration and select Test Integration. OASM posts a test payload to your endpoint. Confirm your service received it and returned a success status.Troubleshooting
No payloads arrive
No payloads arrive
Confirm the URL is reachable from the OASM server, accepts
POST, and is not blocked by a firewall or private-network restriction. If the welcome payload never arrived, the endpoint was unreachable at connect time.The endpoint returns an error
The endpoint returns an error
OASM logs the failure but does not retry. Check the endpoint’s logs for the request, and confirm it returns a
2xx status.Payloads arrive twice
Payloads arrive twice
Use the
timestamp field to deduplicate on your side if your endpoint is called more than once.Related
Notifications
See every event the platform produces
Integrations overview
Learn how events, secrets, and connections work
Vulnerabilities
Review the findings your endpoint will receive
