Webhooks
Quickstart
Create a subscription, receive your first event, verify its signature, and go live. This path takes you from zero to a trusted, real-time webhook.
Create a subscription
Create a subscription in the Atlas dashboard under Settings, then Webhooks, or call the API directly. Both create the same webhook, from two required fields:
url(a public HTTPS endpoint of at most 2,048 characters) andevents(1 to 50 event names, each an exact name, a wildcard such asproject.*, or*).curl -X POST https://api.example.com/v1/webhooks \ -H "Authorization: Bearer atlas_pat_REPLACE_ME" \ -H "Content-Type: application/json" \ -d '{"url":"https://example.com/atlas/webhook","events":["task.completed","project.*"]}'The response returns
{ webhook, secret }. Thewebhookobject holds the webhook details;secret, which starts withwhsec_, is the signing key you use to verify every delivery.Copy your signing secret now
The signing secret is shown only once, at creation. It cannot be retrieved later. If you lose it, rotate the secret: Atlas signs with both the old and the new secret for a grace window, so you can switch without missing a delivery.Receive the event
Stand up an endpoint that returns a
2xxresponse quickly. Atlas waits 15 seconds for an answer, so acknowledge at once and move any heavy work onto a queue of your own rather than doing it inline.javascriptapp.post( "/atlas/webhook", express.raw({ type: "application/json" }), (req, res) => { // verify first (see Security), then enqueue and respond fast res.status(200).send("ok"); }, );Verify every payload
Verify the signature before you trust a payload. The
Atlas-Signatureheader readst=<seconds>,v1=<hex>: compute the HMAC-SHA256 of`${t}.${rawBody}`with your signing secret, compare it with eachv1, and refuse atmore than five minutes from your clock. See Security and signing for verification code in five languages.Go live
Send a test delivery from the dashboard, or call
POST /v1/webhooks/{id}/test-delivery, which sends asubscription.testevent to that webhook alone. Watch it land in the delivery log, confirm your endpoint verified and acknowledged it, then start relying on real events. See Delivery and retries and Events for what happens next.
Next step: secure your endpoint