In Flashduty On-call
Get the push URL in either of the following ways.
Dedicated integration
- In the Flashduty console, go to Channels and open a channel
- Go to Settings → Integrations → Dedicated integration and click Add an integration
- Select Twingate and click Save
- Open the generated integration card and copy the push URL
Shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select Twingate and enter an integration name
- Configure the default route and pick a channel; you can add more rules under Routes afterwards
- Click Save and copy the generated push URL
Configure Twingate
1
Add a webhook
Sign in to the Twingate Admin Console as an admin, go to Settings → Notification Channels, open the Webhooks tab and click Configure Webhook (Add Webhook when one already exists): enter a webhook name, paste the full Flashduty push URL as the URL, and select the notifications to send to it.Recommended: Connectors offline / online, Events sync errors / resolved / requires attention, Integration errors / resolved, Identity provider integration error, Google Workspace sync error, Device integration API token expiration, and Service Account keys expiration. Select Access Requests only if you want them.
2
Test
Click Test Payload next to a notification and Twingate sends a sample notification to the URL. The Connectors offline and online samples have fixed content (connector
delectable-robin in remote network Acme Network). Flashduty recognises them and opens one standalone Info alert that does not touch any real connector’s alert; close it manually. The other samples have the same format as real notifications and Twingate does not mark them as tests, so Flashduty creates alerts from them; close those manually too.Twingate notification webhooks carry no signature header and need no secret. The
integration_key in the push URL acts as the credential; do not publish it.Alert Key
Twingate notifications carry no alert ID, so Flashduty builds the Alert Key from the tenant (
tenant) and the notification group:
The
table of a connector notification lists the affected connectors (connector_name, remote_network, version, link) but has no connector ID. Flashduty tells connectors apart by remote network plus connector name: when one notification lists several connectors, each gets its own alert, and a connector coming online closes only its own alert. When the table names no connector, the connector notifications of one tenant merge into one alert. A renamed connector counts as a new connector. The events sync error notification has no sync_type, so the sync type is not part of its Alert Key.
Changes to the message, timestamp, days_remaining, or table never change the Alert Key. Flashduty rejects a request without tenant or type, or without integration / request_id for the types that need them.
These notifications create no alert and Flashduty returns success: CLIENT_UPDATE_RECOMMENDED, CLIENT_UPDATE_REQUIRED, CONNECTOR_UPGRADE_AVAILABLE.
Severity
Twingate notifications have no severity field, so Flashduty sets it from the type:
A recovery notification keeps the severity of the notification it closes.
Alert content
- Title: the notification
message;Twingate <type>when absent - Description: the access request
reasonand the key-value pairs of everytablerow (at most 20 rows; fields whose name contains key, token, or secret are left out) - Labels:
tenant,type,check(notification group),integration,sync_type,platform,days_remaining,request_id,user_name,resource_name,approval_mode,request_type
Notifications that do not recover
Key and token expiration, Google Workspace sync errors, and access requests are one-shot: Twingate sends no recovery. Turn on auto-close for the channel, with 24 hours as a suggested duration. Repeated notifications for the same object merge into one alert.
Troubleshooting
- Twingate reports a webhook error: the receiver must accept POST with JSON. Confirm you entered the full push URL including
integration_key - The alert did not close after the connector came back: confirm the Connectors online notification is selected. Flashduty matches the online notification by remote network plus connector name; after a connector is renamed, close the alert under the old name manually
- The alert type is not what you expected: check the
typelabel, which is thetypefield of the Twingate notification