Skip to main content
Webhooks tell your server when an action changes state or an owner policy is confirmed or revoked. Delivery is at least once and may be out of order. Deduplicate by event ID and treat polling as the source of truth.

Create an endpoint

In the console, open Webhooks and choose Add endpoint, or call the API:
The URL must be https and resolve to a public address. Redirects are not followed. A project environment can have up to 10 endpoints. Send a test event with Test in the console or sendWebhookTest.

Events

Verify every delivery

Each request carries gol-webhook-id, gol-webhook-timestamp, and gol-webhook-signature. The signature is v1= followed by the hex HMAC-SHA256 of timestamp.rawBody, keyed by the endpoint secret. Verify against the raw body before parsing:
Timestamps more than 5 minutes from your clock are rejected. When you rotate a secret, both secrets sign deliveries for 24 hours; pass both to verifyWebhook during the switch.

Retries

Respond with any 2xx within 10 seconds. Otherwise GOL retries after about 30 seconds, 2, 10, and 30 minutes, 1, 3, 6, and 12 hours, then gives up. Every attempt appears under Recent deliveries in the console and in listWebhookDeliveries. A disabled endpoint keeps pending deliveries for 72 hours.