Webhooks
Set up webhooks to receive real-time notifications from CodeWall.
Webhooks send HTTP POST requests to your endpoint when events occur in CodeWall, enabling real-time integration with any system.
Setting up a webhook
- Go to Settings > Webhooks
- Click Add Webhook
- Enter the destination HTTP(S) URL
- Select the channel type: Webhook (with HMAC signing), Slack, or Microsoft Teams
- Select which events to subscribe to
- For webhook channels, enter a signing secret (minimum 16 characters)
- Click Save
Events
| Event | Description |
|---|---|
finding.created | A new vulnerability was discovered |
finding.high | A high or critical severity finding was discovered |
run.started | A test run was durably created and queued |
run.completed | A test run completed, stopped early, or reached its budget limit |
run.failed | A test run entered a failure state |
run.cancelled | A test run was cancelled |
approval.required | A phase or command approval gate is waiting for a decision |
Channel types
| Type | Description |
|---|---|
| Webhook | Standard HTTP POST with HMAC-SHA256 signing |
| Slack | Posts formatted messages to a Slack incoming webhook URL |
| Teams | Posts formatted messages to a Microsoft Teams incoming webhook URL |
Payload format
Webhook payloads are sent as JSON:
{
"id": "evt_abc123",
"event_type": "finding.created",
"created_at": "2026-04-10T10:30:00Z",
"org_id": "org_abc123",
"data": {
"run_id": "run-20260410-103000-a1b2c3d4",
"project_id": "proj_abc123",
"targets": ["https://example.com"],
"findings_count": 1,
"findings": [
{
"id": 42,
"title": "SQL Injection in /api/users",
"category": "injection",
"severity": "critical",
"verified": true,
"affected_assets": ["https://example.com/api/users"],
"remediation": "Use parameterized queries."
}
]
}
}Verification
Each webhook request includes a signature header (X-CodeWall-Signature) that you can use to verify the payload came from CodeWall. The signature is an HMAC-SHA256 hash of the request body using your webhook secret.
Retry policy
Failed production-event deliveries are retried for transient failures only: timeouts,
HTTP 408/409/425/429, and HTTP 5xx responses. CodeWall makes up to 6 total
attempts with exponential backoff and honours Retry-After for rate limits.
Test events are not retried.
API management
You can also manage webhook endpoints programmatically via the API. See the Webhook Endpoints API for full details.

