Skip to main content
Forge can send the same organization notification events used by Slack and email to one HTTPS endpoint. This is useful for SOAR workflows, ticketing systems, and custom security automation. The event toggles and minimum severity under Settings → Ownership apply to the webhook. Owner-specific delivery preferences remain Slack and email only.

Set up

  1. Open Settings → Ownership.
  2. In Webhook, select Connect webhook.
  3. Enter a public HTTPS endpoint and save it.
  4. Copy the generated signing secret. Forge shows it only once.
  5. Select Send test and return a 2xx response within five seconds.
  6. After the test succeeds, select Enable.
After setup, the Ownership page shows the webhook as Connected. Select Manage to edit the endpoint, send another test, enable or disable delivery, or regenerate the signing secret. Changing the endpoint or regenerating the secret disables delivery until the new configuration passes a test.

Request

Forge sends one notification per request:
owner is included only when the notification has an ownership target. Forge does not include prompts, tool inputs, tool outputs, raw provider events, or arbitrary internal metadata in this payload.

Verify signatures

Requests include: Compute HMAC-SHA256 over <timestamp>.<raw request body> using the signing secret, then compare it to X-Forge-Webhook-Signature with a constant-time comparison. Reject stale timestamps and process repeated webhook IDs idempotently. Forge does not follow redirects. Network errors, timeouts, 408, 429, and 5xx responses are retried up to three attempts. Any 2xx response succeeds; other responses fail permanently.

Tines

Import the tines-forge-notification-story.json Story or create the same flow manually. The Story captures headers and the raw request body, verifies X-Forge-Webhook-Signature with Tines’ HMAC_SHA256 function, and then filters for high and critical notifications. After importing:
  1. Create a restricted Tines text credential with slug forge_webhook_signing_secret.
  2. Copy the one-time signing secret shown by Forge into that credential.
  3. Replace the imported Webhook action’s placeholder path and secret with newly generated random values, then copy its Summary URL into Forge.
  4. Send a Forge test and confirm that Verify Forge signature emits signature_valid: true.
  5. Connect High or critical severity to the case, ticket, Slack, or pager action used by your SOC.
In any custom Story:
  1. Use id as the deduplication key.
  2. Branch on type and severity.
  3. Use subject.type and subject.id for enrichment or ticket correlation.
  4. Include forgeUrl in analyst notifications and cases.
The webhook delivery history in Forge shows attempts and safe error details. Replay a failed delivery from Settings → Ownership after correcting the Story or receiver.

Google Security Operations SOAR

Google SecOps SOAR maps an incoming JSON sample to its alert schema. Download forge-notification.sample.json and upload it under SOAR Settings → Ingestion → Webhooks → Data mapping. Use these minimum mappings: Map priority to an integer: informational → 10, low → 30, medium → 50, high → 70, and critical → 90. Google accepts the Forge ISO 8601 occurredAt value for StartTime. Preserve the full received Forge object in the alert’s EventsList so analysts retain the source fields. Keep DisplayId unique so Google SecOps can deduplicate alerts. Test and enable the mapping in SOAR Settings → Ingestion → Webhooks. Google recommends a webhook for basic mapping and a connector only when advanced, source-specific mapping is required. See Set up a SOAR webhook. Google SecOps’ incoming URL is shown only when the webhook is created. Copy it before leaving the page, configure it in Forge, and use Send test before enabling delivery. Do not configure both a Google webhook and a connector for the same Forge notification stream; Google warns that doing so can create duplicate cases. This notification webhook creates workflow alerts and cases. For continuous, searchable security telemetry, use Security Exports instead.

Other HTTPS receivers

Any receiver that accepts HTTPS JSON can use this integration. Preserve id for idempotency, verify the signature before processing, return 2xx only after accepting the event, and use forgeUrl to send analysts back to the source record.