Skip to content

Webhooks Connector

Webhooks deliver Have I Been Squatted events to an HTTP endpoint in near real time. Payloads follow the Standard Webhooks specification and are signed with an HMAC SHA-256 secret.

  1. In the app, open Connectors > Webhooks.
  2. Click Create webhook and enter a public HTTP(S) URL.
  3. (Optional) Add a description and set event filters.
  4. Save the webhook and copy the signing secret (shown only once).

Webhook payloads are JSON objects with this shape:

{
"type": "lookup_result.alerts",
"timestamp": "2026-02-17T12:34:56Z",
"data": {
"domain": "example.com",
"lookup_id": "2bca4c25-8c47-4a3c-a1d4-9d2a7c8cced5",
"count": 2,
"total": 2,
"has_more": false,
"alerts": [
{
"alert": { "...": "..." },
"result": { "...": "..." }
}
]
}
}

Notes:

  • type is the event name (see below).
  • timestamp is ISO 8601.
  • alerts contains { alert, result } objects derived from lookup results.
  • When more than 25 alerts match, only the first 25 are included and has_more is true (and x-webhook-has-more: true is included).

Webhooks currently deliver these event types:

  • lookup_result.alerts - Alerts that match the configured filters.
  • rule.alert.created.v1 - A detection rule with a webhook response raised an alert.
  • domain.dispatched.v1 - A lookalike domain was sent to this webhook by hand, outside any rule, for example with the MCP server’s dispatch_action tool.
  • test.delivery - Test payloads sent from the UI.

A domain.dispatched.v1 event names the dispatch, the lookalike and the monitored domain it was found for:

{
"type": "domain.dispatched.v1",
"timestamp": "2026-10-07T12:34:56Z",
"data": {
"schema_version": 1,
"dispatch_id": "0b7c2c1e-5d1a-4f0e-9a43-2f6f2f1d9c11",
"result_id": "6a1f0d4e-2c3b-4a5d-8e9f-0a1b2c3d4e5f",
"fqdn": "examp1e-login.com",
"level": "high",
"note": "Credential harvesting page.",
"requested_by": "agent",
"monitored_asset": {
"id": "3f2e1d0c-9b8a-4c7d-6e5f-4a3b2c1d0e9f",
"fqdn": "example.com"
},
"lookup_id": "2bca4c25-8c47-4a3c-a1d4-9d2a7c8cced5"
}
}

note is absent when none was given.

Delivery follows the Standard Webhooks signature scheme. Each request includes:

  • webhook-id - A unique message ID (prefixed with msg_).
  • webhook-timestamp - Unix timestamp (seconds).
  • webhook-signature - HMAC SHA-256 signature in the format v1,<base64>.

The signed content is:

msg_id.timestamp.payload

The secret shown in the UI is hex-encoded. Convert it to raw bytes before computing the HMAC.

Example (Node.js):

import crypto from "crypto";
const msgId = req.headers["webhook-id"];
const timestamp = req.headers["webhook-timestamp"];
const signature = req.headers["webhook-signature"];
const payload = req.rawBody; // exact JSON bytes
const secret = Buffer.from(process.env.WEBHOOK_SIGNING_SECRET, "hex");
const expected = crypto
.createHmac("sha256", secret)
.update(`${msgId}.${timestamp}.${payload}`)
.digest("base64");
const valid = signature === `v1,${expected}`;

Use the Test action to deliver a test.delivery payload to the endpoint. Test requests time out after 10 seconds and are blocked if the URL resolves to a private or internal IP address.

Webhook delivery attempts are recorded in the Webhook audit log with request and response payloads, status, and timing details.