Inbound webhooks
Receive external HTTP POST requests into webhook tasks and ticket actions.
Inbound webhooks
Inbound webhooks let external systems send JSON POST requests into ArxDeck. Authenticated deliveries match route rules, optionally spawn webhook tasks, and can resolve tickets to run nested actions (change status, run agents, emit signals, and more).
Provider webhooks for Cursor or Claude agent status are separate system endpoints — not configured here.
Typical uses
- CI or monitoring systems notifying ArxDeck when a build finishes
- External tools opening or updating tickets when an event occurs
- Test deliveries while designing JSONPath extractions and route predicates
Webhook tasks use the same task template step model with a webhook-specific palette (control flow plus resolve_ticket). Ticket-scoped nested Run agent steps support the same optional typed result fields as workflow templates and scheduled tasks.
Setup & configuration
Project admins configure endpoints at Settings → Webhooks:
- Create endpoint — receive a path token (shown once) and optional HMAC secret.
- Define extractions — JSONPath mappings from the payload to named fields.
- Author webhook tasks — named task graphs with control flow (
Condition,Switch,Loop) andresolve_ticketleaves. - Add route rules — ordered predicates (first match wins) choosing a task or test delivery mode.
- Send test payloads and inspect delivery history (optional raw payload capture for 24 hours when debugging).
Enable or disable endpoints without deleting configuration.
Technical details
| Topic | Detail |
|---|---|
| URL shape | POST https://workspace.arxdeck.ai/api/webhooks/inbound/{token} — token is an unguessable arx_wh_… value |
| Primary auth | Path token (hashed at rest; plaintext shown once on create/rotate) |
| Optional HMAC | Header X-Hub-Signature-256 with sha256= hex digest of the raw body when a secret is configured |
| Failure behavior | Disabled endpoints, archived projects, unknown tokens, and bad HMAC return 401 without leaking endpoint existence |
| Tasks | Up to 10 named tasks per endpoint; routes reference task IDs |
| resolve_ticket | Match ticket by ID, normalized PR URL, or custom field; on unresolved policy success or fail |
| Raw capture | Opt-in 24h window stores bodies for admin inspection; auto-expires; unknown-token traffic is never stored |
Secrets are encrypted at rest on the server. Do not embed tokens in public repositories or client-side apps.
Related
- Task templates & runs
- Workflow automations
- GitHub integration — PR URL resolution in webhook tasks
- Feedback ingest API — different API for user feedback items
