Skip to main content
UpGuard is a third-party risk and attack surface management platform. Create a webhook integration in UpGuard and choose its triggers, for example a company score dropping below a threshold, a vendor score dropping within a period, or a new data leak being published. Every notification it fires is sent to Flashduty On-call. Each UpGuard notification maps to one Flashduty alert. UpGuard sends no “recovered” notification, so alerts are closed by the channel’s auto-close or manually.

In Flashduty On-call


You can get the push URL in either of the following ways.

Use a dedicated integration

  1. In the Flashduty console, select Channels and open a channel
  2. Select Settings → Integrations → Dedicated integrations, then click Add an integration
  3. Select UpGuard and click Save
  4. Open the generated integration card and copy the push URL

Use a shared integration

  1. In the Flashduty console, select Integration Center → Alert events
  2. Select UpGuard and enter an integration name
  3. Configure the default route and choose a channel; you can add more rules under Routes later
  4. Click Save and copy the generated push URL

Configure in UpGuard


1

Add a webhook integration

  1. Sign in to UpGuard, go to Integrations, and add a webhook integration
  2. Select the triggers
  3. Name the integration and paste the full Flashduty push URL, including integration_key, as the webhook destination
2

Fill in the payload template

UpGuard renders the request body from a Liquid template. Flashduty parses the JSON rendered from the template below. Paste it as the payload; string fields must be quoted:
Keep id: a request without notification.id is rejected. The fields under context depend on the trigger; missing fields render empty and Flashduty ignores empty values.
3

Enable the integration and test it

  1. Click Send test message and confirm Flashduty receives an alert. UpGuard’s documentation does not show the test message body, so Flashduty handles it like any notification: it opens an alert that you close by hand
  2. Enable the integration
4

Turn on auto-close

Turn on auto-close in the channel that receives these alerts, with a suggested duration of 7 days. UpGuard sends no recovery notification, so without auto-close these alerts stay open.

Event types


Alert Key


Flashduty uses notification.id as the Alert Key: notifications with different ids open different alerts, and a redelivery with the same id merges into the same alert. A request without notification.id is rejected. UpGuard’s documentation does not state the scope of that id’s uniqueness, so before going live, confirm with the test message and one real trigger that two notifications carry different id values.

Status and severity


UpGuard notifications carry no severity, so every notification opens as Warning. To tell them apart, adjust the severity in the channel’s alert processing rules using the notification_type label.

Labels


The alert title is the description (for example The score for 'Example Company' dropped below 600 with a score of 599), or the notification type when it is empty.

Notes


  • UpGuard notifications can carry breach and identity data. Keep the template to the fields listed above and do not add credentials or personal data
  • UpGuard sends requests from a fixed set of IP addresses, listed in webhook-ips.json. Allow them if an IP allowlist sits in front of Flashduty
  • If description contains a double quote, the rendered JSON is invalid and the request is rejected as a parameter error

Troubleshooting


  • Flashduty receives nothing: confirm the webhook destination is complete, includes integration_key, and the integration is enabled
  • Parameter error: a missing notification.id means the template dropped id; an invalid JSON message means a string field is not quoted
  • Alerts never close: UpGuard sends no recovery notification, so turn on the channel’s auto-close
For more information, see UpGuard’s webhook integration guide.