SignalWatch

Signed webhooks

Send page changes to a webhook you control.

Put an HTTPS URL on a monitor. When the visible text changes, the fetch fails or recovers, or the certificate is near expiry, SignalWatch POSTs a signed JSON event. Slack and Discord URLs get a readable message instead.

No card required. Webhooks are included on the free plan. Add the endpoint in the dashboard after the monitor exists — you do not need it to sign up.

Events

Every payload also includes check_id, name, url, status_code, and detected_at. A worked curl, Python, and n8n version is on the examples page.

A content-change body

{
  "event": "content.changed",
  "check_id": 42,
  "name": "Changelog",
  "url": "https://example.com/changelog",
  "status_code": 200,
  "detected_at": "2026-10-03T12:00:00+00:00",
  "content_hash": "…",
  "change_ratio": 0.04,
  "diff": "-1.8.0\n+1.9.0\n"
}

Presentation example. The diff is truncated for delivery. The dashboard keeps a longer copy for 45 days.

Signature

Each delivery sets:

Compare the header with a constant-time check. The secret is on the dashboard under Webhook signing secret. Rotate the API key separately. The API key does not sign webhooks.

Failed deliveries retry. Use Send test alert if your endpoint returns an error. The dashboard reports the HTTP status or the error string.

Slack and Discord

Paste an incoming webhook URL from Slack (hooks.slack.com) or Discord. Those hosts receive a headline, the URL, and a fenced diff, because they do not render an arbitrary JSON event as a chat message. Signature headers are still present. Any other HTTPS URL receives the JSON above.

Create monitors from the REST API with X-API-Key if the dashboard is the wrong place. The API is on every plan, including Free (3 monitors, 15-minute checks). Faster checks are on Pro and Business.

FAQ

Which webhook events does SignalWatch send?

content.changed with a unified diff, check.down when a fetch fails, check.up when it recovers, cert.expiring when a TLS certificate is inside 14 days and again inside 3, and test when you press Send test alert.

How do I verify the signature?

Compute HMAC-SHA256 over the header X-SignalWatch-Timestamp, a period, and the raw request body, using your account webhook secret. Compare it with X-SignalWatch-Signature, which is prefixed sha256=. The dashboard shows the secret and a short Python check.

Do Slack and Discord get the raw JSON?

No. Incoming webhook URLs on hooks.slack.com and Discord receive a formatted message with a fenced diff. Any other HTTPS URL receives the JSON event. Signature headers are set in both cases.

Related: code examples, TLS expiry, competitor pricing.