Signed webhook

New
Webhook·outbound

Sends a POST with the same payload as a generic webhook, plus an `x-cpum-signature: sha256=<hex>` header so your endpoint can verify the request really came from cpum.ai. Use this when piping into a Lambda, Cloud Function, or your own ingestor.

cpum.ai → Signed webhook
Critical
cpum.ai alert: api.high-latency
Metric: p99_latency_ms
Value: 842.00
Threshold: > 500
Fired at: 2026-05-08T14:22:01Z

Sample payload — your Signed webhook channel receives this shape.

Setup steps

  1. 1Decide on a signing secret at least 16 characters long and store it on the receiver.
  2. 2Paste the receiver URL and the same signing secret into the signed-webhook destination form in cpum.ai.
  3. 3On the receiver, recompute HMAC-SHA256(secret, raw_body_bytes) and compare against `x-cpum-signature` (after stripping the `sha256=` prefix).

What you'll need

FieldExample
Receiver URLhttps://example.com/cpum-hook
Signing secret (>= 16 chars)secretlong random string

Ready to wire it up?

Open the cpum.ai dashboard and we'll pre-fill the Signed webhook destination form for you.

Signed webhook integration — cpum.ai | cpum.ai