Webhooks
Webhooks here are inbound. They are endpoints that vendors post to when something changes on their side, so the CyberOptix CTEM Platform reacts immediately instead of waiting for its next poll.
The platform does not post your events to a URL you nominate. If you want to be told about something, use Notifications for Slack and Teams, or poll the API with an API key.
That distinction matters when planning an integration, because "webhook" usually means the opposite of what it means here.
What posts to us
| Source | Triggers on |
|---|---|
| GitHub | Repository events |
| Azure DevOps | Repository and pipeline events |
| Stripe | Billing and subscription events |
Configuration
You do not configure these by hand. Each is set up as part of connecting the relevant integration:
- GitHub and Azure DevOps - the webhook is registered when you connect the integration under Integrations. Connect the integration and it is done.
- Stripe - billing infrastructure, managed by the platform. Nothing for you to set up.
The useful consequence is that repository changes reflect quickly rather than on a scan cycle: a push or a pull request reaches the platform as it happens.
When something looks stale
If repository data is not updating, the webhook registration is the first thing to check rather than the last:
- Confirm the integration is still connected and its credentials have not expired.
- Check the webhook still exists on the vendor side. Repository permission changes and organization-level policy can remove it without the integration appearing broken.
- Reconnect the integration, which re-registers the webhook.
A revoked or expired token usually presents as "data stopped updating" rather than as an error, because nothing is failing - the vendor has simply stopped calling.
Building your own integration
To drive the platform from your own systems, use an API key rather than waiting to be called. The API reference documents every endpoint, and key scopes narrow what a program can reach.
API
The endpoints behind this section are in the API reference.
Next
- Integrations - connecting a vendor
- API keys - driving the platform programmatically
- Notifications - being told when something happens