Incident response
MonoDuty Webhooks
Create MonoDuty Webhooks, send the production JSON payload, and handle validation, idempotent retries, conflicts, and token rotation.
Webhooks
MonoDuty accepts native JSON over HTTPS at a source-specific URL:
The endpoint is intentionally tool-neutral. A sender or adapter must map its native payload to the fields below.
Create and own a source
- Create or select the team-owned service.
- Create an explicit Webhook source.
- Copy the one-time URL into the sender's secret configuration.
- Send a controlled test and verify the owning team, incident, and notification route.
Rotate the source token immediately if the URL is exposed.
Payload contract
At least one of title or message is required. Unknown provider-native wrappers are not automatically transformed.
| Field | Requirement | Limit |
|---|---|---|
title | Required when message is absent | 255 characters |
message | Required when title is absent | 10,000 characters |
description | Optional string | 10,000 characters |
severity | Optional: CRITICAL, HIGH, MEDIUM, LOW | Enum |
dedup_key | Optional fallback for Idempotency-Key | 191 characters |
source | Optional source label | 191 characters |
metadata | Optional JSON object/array | Bounded depth, count, and string length |
{
"title": "Database replication lag",
"severity": "HIGH",
"description": "Replica lag exceeded 30 seconds",
"source": "prometheus-transformer",
"metadata": {"cluster":"prod-mysql-01"}
}Security and retries
The current contract authenticates with the high-entropy token in the URL over HTTPS. It does not advertise HMAC request signing. Keep the URL secret, rotate it after exposure, and do not place it in query strings, analytics, or access logs.
Use a stable Idempotency-Key for retries. Same key plus the canonically identical payload returns HTTP 200, the original incident, and duplicate: true. The same key with a different payload returns HTTP 409 with code idempotency_conflict. Replays never update an incident.