In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select HackerOne, then click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select HackerOne and enter an integration name
- Configure the default route and select a channel; after creation, add more rules under Route if needed
- Click Save and copy the generated Push URL
Configure HackerOne
Webhooks are configured per program and inherit the permissions of the user who creates them: that user must be able to see the program’s reports and change its settings.
1
Create a webhook
- Sign in to HackerOne, go to Engagements, open the menu next to the program, and select Settings
- Go to Automation → Webhooks and click New webhook
- Paste the full Flashduty push URL into Payload URL. The URL must include
integration_key - You can leave Secret empty. Flashduty identifies the integration by the
integration_keyin the push URL and does not verify theX-H1-Signatureheader
2
Select events
Select Let me specify individual events and check the following events:
Add events such as
report_needs_more_info or report_retesting if needed; they only update the alert of the same report. Then click Add webhook.You can also select Send me everything. Comment, bounty, and other events are handled by the report’s current state as well: they update the alert while the report is open and create no new alert after it is closed. Program events such as program_hacker_joined carry no report; Flashduty returns success and creates no alert.3
Verify the lifecycle
Submit or triage a report and confirm that Flashduty receives an active alert. Then close the report in HackerOne (for example, as Resolved) and confirm that the alert recovers.When editing the webhook, you can click Test request to send an example request and confirm that the URL is reachable. If the example request creates an alert in Flashduty, close it manually. The Recent deliveries section of the webhook edit page shows each request and Flashduty’s response.
Alert Key
Flashduty uses the report ID (
data.report.id in the webhook) as the Alert Key. Every HackerOne delivery carries the full report, and the same report has the same data.report.id when it is submitted, triaged, closed, or reopened. It is also the number in the report URL https://hackerone.com/reports/<id>.
Changes to the title, state, or severity do not change the Alert Key. Deliveries that contain a report without data.report.id are rejected.
Status and severity
The report’s current state (
data.report.attributes.state), not the event name, sets the alert status:
Other state values are rejected, and the delivery shows as failed in HackerOne’s Recent deliveries.
The report severity (
data.report.relationships.severity.data.attributes.rating) sets the alert severity:
When triage changes a report’s severity, the alert is updated with the new severity.
Labels
The alert description is the report’s vulnerability information (
vulnerability_information), truncated beyond 8 KB.
Troubleshooting
- HackerOne shows a failed delivery: Open the failed request under Recent deliveries on the webhook edit page and check Flashduty’s reply on the Response tab. Make sure the Payload URL is complete and includes
integration_key - The alert does not recover: Make sure
report_resolvedand all fourreport_closed_as_*events are checked. Close alerts manually in Flashduty for reports that were closed while those events were not selected - Some reports are missing: The webhook inherits its creator’s permissions. Make sure the creator can see those reports