Skip to main content
Use the webhook of a HackerOne program to send vulnerability reports to Flashduty On-call. Each HackerOne report maps to one Flashduty alert: submitting, triaging, or reopening a report triggers or updates that alert, and the alert recovers when the report is resolved or closed in any other way.

In Flashduty On-call


You can obtain an integration push URL in either of the following ways.

Use a dedicated integration

  1. In the Flashduty console, select Channel and open a channel
  2. Select Configuration → Integrations → Private integration, then click Add an integration
  3. Select HackerOne, then click Save
  4. Open the generated integration card and copy the Push URL

Use a shared integration

  1. In the Flashduty console, select Integration Center → Alert Events
  2. Select HackerOne and enter an integration name
  3. Configure the default route and select a channel; after creation, add more rules under Route if needed
  4. Click Save and copy the generated Push URL

Configure HackerOne


Webhooks are configured per program and inherit the permissions of the user who creates them: that user must be able to see the program’s reports and change its settings.
1

Create a webhook

  1. Sign in to HackerOne, go to Engagements, open the menu next to the program, and select Settings
  2. Go to Automation → Webhooks and click New webhook
  3. Paste the full Flashduty push URL into Payload URL. The URL must include integration_key
  4. You can leave Secret empty. Flashduty identifies the integration by the integration_key in the push URL and does not verify the X-H1-Signature header
2

Select events

Select Let me specify individual events and check the following events:Add events such as report_needs_more_info or report_retesting if needed; they only update the alert of the same report. Then click Add webhook.
You must check report_resolved and all four report_closed_as_* events. Otherwise, alerts in Flashduty do not recover when reports are closed.
You can also select Send me everything. Comment, bounty, and other events are handled by the report’s current state as well: they update the alert while the report is open and create no new alert after it is closed. Program events such as program_hacker_joined carry no report; Flashduty returns success and creates no alert.
3

Verify the lifecycle

Submit or triage a report and confirm that Flashduty receives an active alert. Then close the report in HackerOne (for example, as Resolved) and confirm that the alert recovers.When editing the webhook, you can click Test request to send an example request and confirm that the URL is reachable. If the example request creates an alert in Flashduty, close it manually. The Recent deliveries section of the webhook edit page shows each request and Flashduty’s response.

Alert Key


Flashduty uses the report ID (data.report.id in the webhook) as the Alert Key. Every HackerOne delivery carries the full report, and the same report has the same data.report.id when it is submitted, triaged, closed, or reopened. It is also the number in the report URL https://hackerone.com/reports/<id>. Changes to the title, state, or severity do not change the Alert Key. Deliveries that contain a report without data.report.id are rejected.

Status and severity


The report’s current state (data.report.attributes.state), not the event name, sets the alert status: Other state values are rejected, and the delivery shows as failed in HackerOne’s Recent deliveries. The report severity (data.report.relationships.severity.data.attributes.rating) sets the alert severity: When triage changes a report’s severity, the alert is updated with the new severity.

Labels


The alert description is the report’s vulnerability information (vulnerability_information), truncated beyond 8 KB.

Troubleshooting


  • HackerOne shows a failed delivery: Open the failed request under Recent deliveries on the webhook edit page and check Flashduty’s reply on the Response tab. Make sure the Payload URL is complete and includes integration_key
  • The alert does not recover: Make sure report_resolved and all four report_closed_as_* events are checked. Close alerts manually in Flashduty for reports that were closed while those events were not selected
  • Some reports are missing: The webhook inherits its creator’s permissions. Make sure the creator can see those reports
For field details, see HackerOne Webhooks and HackerOne Help Center: Webhooks.