Documentation

Webhooks

Receive every event as JSON and build your own automation.

Notifications

Webhooks

Receive every event as JSON and build your own automation.

A webhook contact receives an HTTP POST for each event. Requests are retried three times with a short back-off if your endpoint does not answer with a 2xx status within 10 seconds.

Example payload
json
{
  "event": "down",
  "timestamp": "2026-10-02T10:20:30.000Z",
  "message": "Unexpected HTTP status 503",
  "monitor": {
    "id": "clx…",
    "name": "Public API",
    "type": "HTTP",
    "target": "https://api.example.com/health",
    "status": "DOWN",
    "url": "https://monitermysite.com/app/monitors/clx…"
  },
  "incident": {
    "id": "cly…",
    "started_at": "2026-10-02T10:20:30.000Z",
    "resolved_at": null,
    "regions": ["nyc3", "fra1"],
    "cause": "Unexpected HTTP status 503"
  }
}

The event field is one of down, up, slow, ssl_expiry or test. Recovery payloads include resolved_at and duration_sec.

Verifying signatures

If you set a signing secret on the contact, every request carries X-MoniterMySite-Timestamp and X-MoniterMySite-Signature headers. The signature is an HMAC-SHA256 of the timestamp, a dot and the raw request body, using your secret. Reject requests whose timestamp is older than five minutes to prevent replays.

Node.js
js
import { createHmac, timingSafeEqual } from "node:crypto";

export function verify(rawBody, headers, secret) {
  const ts = headers["x-monitermysite-timestamp"];
  const sig = headers["x-monitermysite-signature"] ?? "";
  const expected = "sha256=" + createHmac("sha256", secret).update(ts + "." + rawBody).digest("hex");
  return sig.length === expected.length && timingSafeEqual(Buffer.from(sig), Buffer.from(expected));
}
Python
python
import hmac, hashlib

def verify(raw_body: bytes, headers: dict, secret: str) -> bool:
    ts = headers.get("x-monitermysite-timestamp", "")
    sig = headers.get("x-monitermysite-signature", "")
    expected = "sha256=" + hmac.new(secret.encode(), f"{ts}.".encode() + raw_body, hashlib.sha256).hexdigest()
    return hmac.compare_digest(sig, expected)

Didn’t find what you need?

We answer every email, usually within one business day.

Email support