Skip to content

Inbound webhooks

GitHub webhook

POST/hooks/github/:wid

Pull request events, verified against x-hub-signature-256. A merged PR marks linked tasks accepted; one closed without merging marks them rejected.

#Authentication

Issuer signature

No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read.

GitHub's x-hub-signature-256 header, checked with the secret saved when the GitHub integration was connected.

#Path parameters

widstringrequired

Workspace id