Signed webhooks
Create tasks from any system with a signed JSON POST — signature, idempotency, templates for title and prompt, and signed callbacks.
Send a delivery
POST JSON to the webhook URL with:
X-AO-Signature: sha256=<hex HMAC-SHA256 of the raw body, keyed with the secret>X-AO-Delivery: <unique id>(optional) — retries with the same id create one task. Without it, an identical body counts as the same delivery.
BODY='{"ticket":{"key":"OPS-42","summary":"Rotate the staging certificate"}}'
SIG=$(printf '%s' "$BODY" | openssl dgst -sha256 -hmac "$SECRET" | sed 's/^.* //')
curl -X POST "$HOOK_URL" -H "Content-Type: application/json" \
-H "X-AO-Signature: sha256=$SIG" -H "X-AO-Delivery: ops-42-1" --data "$BODY"Templates
The title and prompt come from templates where placeholders in double curly braces are replaced with values from
the JSON — for example [{{ticket.key}}] {{ticket.summary}}.
Callback
With a callback URL, the outcome is POSTed there when the task completes, fails or needs attention:
{ taskId, status, title, summary, url, ref }, signed the same way in X-AO-Signature.
With REQUIRE_PUBLIC_CALLBACK_URLS=true (the default when DEPLOYMENT_MODE=cloud, and so on the managed cloud),
callback URLs must be public https addresses, so tenants of a shared installation cannot reach its private network.
Tools that cannot sign
The signature is required. For a system that can only send unsigned webhooks, put a small relay in between that adds the signature.