> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# HackerOne alert integration

> Send submitted, triaged, and closed vulnerability report events from a HackerOne program to Flashduty On-call through a webhook.

Use the webhook of a HackerOne program to send vulnerability reports to Flashduty On-call. Each HackerOne report maps to one Flashduty alert: submitting, triaging, or reopening a report triggers or updates that alert, and the alert recovers when the report is resolved or closed in any other way.

<div className="hide">
  ## In Flashduty On-call

  ***

  You can obtain an integration push URL in either of the following ways.

  ### Use a dedicated integration

  1. In the Flashduty console, select **Channel** and open a channel
  2. Select **Configuration** → **Integrations** → **Private integration**, then click **Add an integration**
  3. Select **HackerOne**, then click **Save**
  4. Open the generated integration card and copy the **Push URL**

  ### Use a shared integration

  1. In the Flashduty console, select **Integration Center → Alert Events**
  2. Select **HackerOne** and enter an integration name
  3. Configure the default route and select a channel; after creation, add more rules under **Route** if needed
  4. Click **Save** and copy the generated **Push URL**
</div>

## Configure HackerOne

***

Webhooks are configured per program and inherit the permissions of the user who creates them: that user must be able to see the program's reports and change its settings.

<Steps>
  <Step title="Create a webhook">
    1. Sign in to HackerOne, go to **Engagements**, open the menu next to the program, and select **Settings**
    2. Go to **Automation → Webhooks** and click **New webhook**
    3. Paste the full Flashduty push URL into **Payload URL**. The URL must include `integration_key`
    4. You can leave **Secret** empty. Flashduty identifies the integration by the `integration_key` in the push URL and does not verify the `X-H1-Signature` header
  </Step>

  <Step title="Select events">
    Select **Let me specify individual events** and check the following events:

    | HackerOne event | Report state | Effect in Flashduty |
    | :- | :- | :- |
    | `report_created` | `new` | Triggers an alert |
    | `report_triaged` | `triaged` | Updates the alert |
    | `report_reopened` | An open state | Triggers or updates the alert |
    | `report_resolved` | `resolved` | Recovers the alert |
    | `report_closed_as_duplicate` | `duplicate` | Recovers the alert |
    | `report_closed_as_informative` | `informative` | Recovers the alert |
    | `report_closed_as_not_applicable` | `not-applicable` | Recovers the alert |
    | `report_closed_as_spam` | `spam` | Recovers the alert |

    Add events such as `report_needs_more_info` or `report_retesting` if needed; they only update the alert of the same report. Then click **Add webhook**.

    <Warning>
      You must check `report_resolved` and all four `report_closed_as_*` events. Otherwise, alerts in Flashduty do not recover when reports are closed.
    </Warning>

    You can also select **Send me everything**. Comment, bounty, and other events are handled by the report's current state as well: they update the alert while the report is open and create no new alert after it is closed. Program events such as `program_hacker_joined` carry no report; Flashduty returns success and creates no alert.
  </Step>

  <Step title="Verify the lifecycle">
    Submit or triage a report and confirm that Flashduty receives an active alert. Then close the report in HackerOne (for example, as **Resolved**) and confirm that the alert recovers.

    When editing the webhook, you can click **Test request** to send an example request and confirm that the URL is reachable. If the example request creates an alert in Flashduty, close it manually. The **Recent deliveries** section of the webhook edit page shows each request and Flashduty's response.
  </Step>
</Steps>

## Alert Key

***

Flashduty uses the report ID (`data.report.id` in the webhook) as the Alert Key. Every HackerOne delivery carries the full report, and the same report has the same `data.report.id` when it is submitted, triaged, closed, or reopened. It is also the number in the report URL `https://hackerone.com/reports/<id>`.

Changes to the title, state, or severity do not change the Alert Key. Deliveries that contain a report without `data.report.id` are rejected.

## Status and severity

***

The report's current state (`data.report.attributes.state`), not the event name, sets the alert status:

| Report state | Alert status |
| :- | :- |
| `new`, `pending-program-review`, `triaged`, `needs-more-info`, `retesting` | Triggered |
| `resolved`, `not-applicable`, `informative`, `duplicate`, `spam` | Recovered |

Other state values are rejected, and the delivery shows as failed in HackerOne's **Recent deliveries**.

The report severity (`data.report.relationships.severity.data.attributes.rating`) sets the alert severity:

| HackerOne severity | Flashduty severity |
| :- | :- |
| `critical` | Critical |
| `high` | Critical |
| `medium` | Warning |
| `low` | Info |
| `none` | Info |
| Unrated or other values | Warning |

When triage changes a report's severity, the alert is updated with the new severity.

## Labels

***

| Label | Source |
| :- | :- |
| `report_id` | Report ID, which is the Alert Key |
| `report_state` | Current report state |
| `severity_rating` | HackerOne severity |
| `event` | Event name of this delivery (the `X-H1-Event` header) |
| `reporter` | Username of the researcher who submitted the report |
| `url` | Link to the report in HackerOne |
| `check` | Report title |

The alert description is the report's vulnerability information (`vulnerability_information`), truncated beyond 8 KB.

## Troubleshooting

***

* **HackerOne shows a failed delivery**: Open the failed request under **Recent deliveries** on the webhook edit page and check Flashduty's reply on the **Response** tab. Make sure the **Payload URL** is complete and includes `integration_key`
* **The alert does not recover**: Make sure `report_resolved` and all four `report_closed_as_*` events are checked. Close alerts manually in Flashduty for reports that were closed while those events were not selected
* **Some reports are missing**: The webhook inherits its creator's permissions. Make sure the creator can see those reports

For field details, see [HackerOne Webhooks](https://api.hackerone.com/webhooks/) and [HackerOne Help Center: Webhooks](https://docs.hackerone.com/en/articles/8588351-webhooks).
