Set up
- Open Settings → Ownership.
- In Webhook, select Connect webhook.
- Enter a public HTTPS endpoint and save it.
- Copy the generated signing secret. Forge shows it only once.
- Select Send test and return a
2xxresponse within five seconds. - After the test succeeds, select Enable.
Request
Forge sends one notification per request:owner is included only when the notification has an ownership target. Forge
does not include prompts, tool inputs, tool outputs, raw provider events, or
arbitrary internal metadata in this payload.
Verify signatures
Requests include:
Compute HMAC-SHA256 over
<timestamp>.<raw request body> using the signing
secret, then compare it to X-Forge-Webhook-Signature with a constant-time
comparison. Reject stale timestamps and process repeated webhook IDs
idempotently.
Forge does not follow redirects. Network errors, timeouts, 408, 429, and
5xx responses are retried up to three attempts. Any 2xx response succeeds;
other responses fail permanently.
Tines
Import thetines-forge-notification-story.json
Story or create the same flow manually. The Story captures headers and the raw
request body, verifies X-Forge-Webhook-Signature with Tines’
HMAC_SHA256 function, and then filters for high and critical notifications.
After importing:
- Create a restricted Tines text credential with slug
forge_webhook_signing_secret. - Copy the one-time signing secret shown by Forge into that credential.
- Replace the imported Webhook action’s placeholder path and secret with newly generated random values, then copy its Summary URL into Forge.
- Send a Forge test and confirm that Verify Forge signature emits
signature_valid: true. - Connect High or critical severity to the case, ticket, Slack, or pager action used by your SOC.
- Use
idas the deduplication key. - Branch on
typeandseverity. - Use
subject.typeandsubject.idfor enrichment or ticket correlation. - Include
forgeUrlin analyst notifications and cases.
Google Security Operations SOAR
Google SecOps SOAR maps an incoming JSON sample to its alert schema. Downloadforge-notification.sample.json
and upload it under SOAR Settings → Ingestion → Webhooks → Data mapping.
Use these minimum mappings:
Map priority to an integer:
informational → 10, low → 30, medium →
50, high → 70, and critical → 90. Google accepts the Forge ISO 8601
occurredAt value for StartTime. Preserve the full received Forge object in
the alert’s EventsList so analysts retain the source fields.
Keep DisplayId unique so Google SecOps can deduplicate alerts. Test and
enable the mapping in SOAR Settings → Ingestion → Webhooks. Google
recommends a webhook for basic mapping and a connector only when advanced,
source-specific mapping is required. See Set up a SOAR webhook.
Google SecOps’ incoming URL is shown only when the webhook is created. Copy it
before leaving the page, configure it in Forge, and use Send test before
enabling delivery. Do not configure both a Google webhook and a connector for
the same Forge notification stream; Google warns that doing so can create
duplicate cases.
This notification webhook creates workflow alerts and cases. For continuous,
searchable security telemetry, use Security Exports
instead.
Other HTTPS receivers
Any receiver that accepts HTTPS JSON can use this integration. Preserveid
for idempotency, verify the signature before processing, return 2xx only
after accepting the event, and use forgeUrl to send analysts back to the
source record.