Skip to main content
integration · custom-webhook

Custom Webhook Integration — Pipe ZopNight Events Into Anything

What does the Custom Webhook integration do?

A custom webhook receives every ZopNight event as JSON at any HTTPS endpoint you control. It is the escape hatch for anything the 4 built-in channels do not cover (PagerDuty, ServiceNow, an internal bot, or your own queue), with the same per-channel event subscriptions.

Coverage by category

If your team’s tooling isn’t on the standard channel list, the custom webhook gets you there. ZopNight will POST structured JSON to any HTTPS endpoint you control, for any event you subscribe to: scheduling, budgets, anomalies, remediation, platform alerts. Custom headers and bearer authentication are optional.

A Slack-compatible JSON envelope, throttled and SSRF-checked

Payloads use a Slack-compatible envelope so many tools accept them unmodified: a top-level text plus an attachments array carrying color, title (‘ZopNight Alert’), body text, priority fields and timestamp, alongside explicit priority (0 = info, 1 = warning, 2 = critical) and priority_label fields. Requests are sent with User-Agent ZopNight-Notification-Service/1.0, your custom headers, and Authorization: Bearer if you configure a token. Delivery is throttled to one message per second per channel with automatic retries. Endpoints are SSRF-validated: public HTTPS only.

From HTTPS endpoint to a test notification

  1. Stand up an HTTPS endpoint that accepts POST JSON.
  2. In ZopNight: Settings > Notifications > Add Channel > Custom Webhook.
  3. Paste the URL; optionally add custom headers and an auth token.
  4. Pick the events and scopes to subscribe, then send a test notification.

Every event family, plus action callbacks

Every ZopNight event family as structured JSON. Optional custom headers and bearer token. Functional action callbacks. Slack-compatible payload shape for drop-in reuse.

When to reach for it

Use a custom webhook when the destination is not Slack, Teams, Google Chat or email. That covers PagerDuty and ServiceNow, neither of which has a first-class channel today, as well as internal tooling and anything that just needs the raw event.

What you receive

The event payload as JSON, with the same fields the built-in cards render from: event type, severity, the resource or budget involved, and a deep link. Because it is raw rather than formatted, you decide how it renders on the far side.

The endpoint is yours to secure

ZopNight posts to the URL you provide over HTTPS. Anything reachable at that URL can receive events, so treat the URL as a secret and verify on your side rather than relying on obscurity.

Limits worth knowing before you connect

Private, loopback and internal network addresses are rejected by design. Plan for at-least-once delivery and idempotent handling.

faq · custom-webhook

Custom Webhook integration: common questions

Can I point a custom webhook at an internal URL?

No. Endpoints are validated against SSRF and must be public HTTPS. Private, loopback and internal network addresses are rejected by design.

Could the same event arrive twice?

Yes, so handle it idempotently. Delivery is at-least-once with automatic retries, throttled to one message per second per channel.

How do I get ZopNight events into PagerDuty or ServiceNow?

Through a custom webhook. Neither has a first-class channel today, so the raw JSON event is the route, and you decide how it renders on your side.

no live rules

No active rule family targets Custom Webhook Integration — Pipe ZopNight Events Into Anything today. Rules that used to are retired, and retired rules publish no pages and fire no findings. Scheduling and permissions coverage are unaffected.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·