Creates a destination. The endpoint is validated BEFORE anything is persisted: a
rejected URL leaves no row and opens no socket.
A webhook's signing secret is supplied here as the MATERIAL, and is MANDATORY on
create: a webhook declared without one is rejected with 400 rather than persisted. The
platform never sends an unsigned webhook, so an unsigned destination is one no alert
could ever be delivered to — a saved row and a green form that go quiet forever. (On
replace the secret is optional, where omitting it means "leave the sealed value
alone".) Its custody reference is derived server-side from the created row's immutable
id and is never accepted from the caller — the custody registry is shared with the IdP,
event-forwarding and observability subsystems, so a caller-supplied reference would let
this destination bind to a credential it has no claim to.
A webhook URL is validated STRICTLY regardless of deployment type, as is any
destination whose purpose is HEARTBEAT.
Authorization: admin.platform.alerts.write.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||