Outgoing webhooks
Configure HTTPS endpoints (Settings → Webhooks) for events such as vulnerability.critical, cra_case.deadline_3h, incident.created, sbom.processed, release_gate.blocked. Payloads are identifier-level; fetch details through the API.
Signature
X-Vellaci-Signature: t=<unix>,v1=<hex> where v1 = HMAC-SHA256(secret, t + "." + body). Verify in constant time; reject if |now − t| > 300s. Rotating a secret keeps the previous one valid for 24 hours.
Delivery
Exponential backoff for up to 8 attempts; dead letters are visible with the last response and can be retried manually; an endpoint is disabled after 50 consecutive failures and admins are notified.
Last updated . This page describes the current release.