Webhooks
Inbound webhooks that create tasks, their management endpoints, and outbound callbacks when tasks finish.
Inbound
POST /api/v1/hooks/:id receives deliveries for an integration: GitHub (X-Hub-Signature-256), GitLab
(X-Gitlab-Token) or signed JSON (X-AO-Signature, optional X-AO-Delivery). See Signed webhooks.
| Answer | Meaning |
|---|---|
201 {"status":"created","taskId":"…"} | A task was created |
200 {"status":"duplicate"} | The same item was delivered before; the existing task stands |
200 {"status":"ignored"} | Not relevant (wrong label, bot comment, disabled integration) |
200 {"status":"pong"} | GitHub's ping |
401 | Bad signature |
Managing integrations
| Method and path | Purpose |
|---|---|
GET /orgs/:orgId/integrations | List |
POST /orgs/:orgId/integrations | Create; the secret is returned once |
PATCH /orgs/:orgId/integrations/:id | Change |
POST /orgs/:orgId/integrations/:id/rotate-secret | New secret, returned once |
DELETE /orgs/:orgId/integrations/:id | Delete |
All require settings.manage.
Outbound callbacks
A signed-webhook integration with a callback URL receives { taskId, status, title, summary, url, ref } when the task
completes, fails or needs attention, signed in X-AO-Signature with the integration's secret. For every task of a scope,
whatever created it, use a completion webhook plugin.