Webhooks
A webhook notifies one of your systems as soon as something happens in goPrevina: an incident is recorded, a training session is completed or the status of a compliance requirement changes. goPrevina sends the event to the URL you give, signed with HMAC-SHA256 in the X-Webhook-Signature header.
1. What is on the screen
The «Create a webhook» block with «Name», «Target URL» and the list of «Events» that can be sent: «incident.created» (incident recorded), «training.session.completed» (training session completed) and «compliance.status.changed» (compliance status changed). Below are the webhooks created; if there are none it says «No webhooks yet.».
2. Create a webhook
1. Enter a «Name» and the «Target URL» (the HTTPS address of your system that will receive the events).
2. Tick at least one event.
3. Press «Create a webhook».
4. The signing secret appears with the warning “Copy this signing secret now — it will not be shown again:”. Store it in your system: with it, your system checks that each request comes from goPrevina by computing the HMAC-SHA256 of the body and comparing it with the X-Webhook-Signature header.
3. Check deliveries and disable
Each webhook in the list has “Delivery history” (event, status, attempts, response code and date of each send), “Enable / disable” and “Delete”. If your URL fails 5 times in a row, goPrevina marks it “auto-disabled” and stops sending: fix your system, check the history and enable it again.
4. What your system receives
Each event arrives as a POST request with a JSON body and two headers: X-Webhook-Event, with the event name, and X-Webhook-Signature, with the signature. Your system must answer with a 2xx code; any other answer counts as a failure, is retried and appears in the “Delivery history”.