Connect your receiver
- Open Settings → Account → Notifications and find Webhook.
- Enter your receiver’s HTTP or HTTPS URL.
- Enter a signing secret if your receiver will verify requests.
- Enable the channel and choose Connect webhook.
- Add an active workspace rule, enable the webhook channel, choose the projects to include, and save.
Payload
Kaneo sends a JSON POST with these fields:
A notification needs a resolvable workspace context for external delivery. It must also pass the active workspace rule and project selection.
Verify requests
When a signing secret is set, Kaneo sendsX-Kaneo-Signature: the lowercase hexadecimal HMAC-SHA256 digest of the exact JSON body. Verify the raw body before parsing it, using a constant-time comparison. Use the notification ID to avoid processing the same notification twice.
The API needs NOTIFICATION_SECRET_ENCRYPTION_KEY to save the signing secret. Private receivers also need KANEO_ALLOW_PRIVATE_WEBHOOK_DESTINATIONS; see server settings.