Outbound Webhooks

How Guard POSTs open-risk notifications to your endpoint from Settings → Notifications.

The Outbound Webhooks card on Settings → Notifications sends notifications for open risks to an external URL. The card reads Send security notifications to external systems via webhooks.

Settings Notifications tab with inbound and outbound webhooks (dark mode)

This is separate from the Inbound Webhook on the same tab, which receives objects into Guard.

Only users who can manage settings see Add Webhook and Delete.

Add a webhook

  1. Open Settings → Notifications.
  2. Click Add Webhook.
  3. Fill in the form:

Add outbound webhook modal (dark mode)

Field

Required

Description

Webhook Name

Yes

A name to identify the webhook in the table.

Webhook URL

Yes

The endpoint that receives the notifications. It must accept POST.

Authentication Header Name

No

The header name to send, for example Authorization.

Authentication Header Value

No

The value to send in that header.

Severity Threshold

Yes

The minimum risk severity that triggers a notification. Default: Medium.

Edit or remove a webhook

Click Edit on a row to open Webhook Configuration. Only Severity Threshold can be changed there. The URL, header, and token are stored securely, can't be viewed after creation, and appear masked. Saving shows Webhook updated.

To change the URL or authentication, delete the webhook and add a new one.

Severity Threshold options are Critical, High, Medium, Low, and Info. Each option includes every higher severity, so Medium also sends High and Critical risks.