> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# UpGuard Alert Integration

> Send UpGuard risk notifications, such as security score drops and new data leaks, to Flashduty On-call through a webhook integration.

UpGuard is a third-party risk and attack surface management platform. Create a webhook integration in UpGuard and choose its triggers, for example a company score dropping below a threshold, a vendor score dropping within a period, or a new data leak being published. Every notification it fires is sent to Flashduty On-call. Each UpGuard notification maps to one Flashduty alert. UpGuard sends no "recovered" notification, so alerts are closed by the channel's auto-close or manually.

<div className="hide">
  ## In Flashduty On-call

  ***

  You can get the push URL in either of the following ways.

  ### Use a dedicated integration

  1. In the Flashduty console, select **Channels** and open a channel
  2. Select **Settings** → **Integrations** → **Dedicated integrations**, then click **Add an integration**
  3. Select **UpGuard** and click **Save**
  4. Open the generated integration card and copy the **push URL**

  ### Use a shared integration

  1. In the Flashduty console, select **Integration Center → Alert events**
  2. Select **UpGuard** and enter an integration name
  3. Configure the default route and choose a channel; you can add more rules under **Routes** later
  4. Click **Save** and copy the generated **push URL**
</div>

## Configure in UpGuard

***

<Steps>
  <Step title="Add a webhook integration">
    1. Sign in to UpGuard, go to **Integrations**, and add a webhook integration
    2. Select the triggers
    3. Name the integration and paste the full Flashduty push URL, including `integration_key`, as the webhook destination
  </Step>

  <Step title="Fill in the payload template">
    UpGuard renders the request body from a Liquid template. Flashduty parses the JSON rendered from the template below. Paste it as the payload; string fields must be quoted:

    ```json theme={null}
    {
      "notification": {
        "id": "{{ notification.id }}",
        "type": "{{ notification.type }}",
        "description": "{{ notification.description }}",
        "occurredAt": "{{ notification.occurredAt }}",
        "context": {
          "LatestScore": "{{ notification.context.LatestScore }}",
          "PrevScore": "{{ notification.context.PrevScore }}",
          "Threshold": "{{ notification.context.Threshold }}",
          "Domain": "{{ notification.context.Domain }}"
        }
      }
    }
    ```

    Keep `id`: a request without `notification.id` is rejected. The fields under `context` depend on the trigger; missing fields render empty and Flashduty ignores empty values.
  </Step>

  <Step title="Enable the integration and test it">
    1. Click **Send test message** and confirm Flashduty receives an alert. UpGuard's documentation does not show the test message body, so Flashduty handles it like any notification: it opens an alert that you close by hand
    2. Enable the integration
  </Step>

  <Step title="Turn on auto-close">
    Turn on [auto-close](/en/on-call/channel/create-edit) in the channel that receives these alerts, with a suggested duration of 7 days. UpGuard sends no recovery notification, so without auto-close these alerts stay open.
  </Step>
</Steps>

## Event types

***

| Payload | Effect in Flashduty |
| :- | :- |
| A notification from any trigger | Opens one alert with severity Warning |

## Alert Key

***

Flashduty uses `notification.id` as the Alert Key: notifications with different ids open different alerts, and a redelivery with the same id merges into the same alert. A request without `notification.id` is rejected. UpGuard's documentation does not state the scope of that id's uniqueness, so before going live, confirm with the test message and one real trigger that two notifications carry different `id` values.

## Status and severity

***

UpGuard notifications carry no severity, so every notification opens as Warning. To tell them apart, adjust the severity in the channel's alert processing rules using the `notification_type` label.

## Labels

***

| Label | Source |
| :- | :- |
| `check` | Notification type (`notification.type`, such as `CustomerCSTARUnderThreshold`) |
| `notification_id` | Notification id |
| `notification_type` | Notification type |
| `occurred_at` | When the notification occurred (`occurredAt`) |
| `latest_score` / `previous_score` / `threshold` | Latest score, previous score and threshold (`context`) |
| `domain` | Related domain (`context.Domain`) |

The alert title is the `description` (for example `The score for 'Example Company' dropped below 600 with a score of 599`), or the notification type when it is empty.

## Notes

***

* UpGuard notifications can carry breach and identity data. Keep the template to the fields listed above and do not add credentials or personal data
* UpGuard sends requests from a fixed set of IP addresses, listed in [webhook-ips.json](https://cdn.cyber-risk.upguard.com/webhook-ips.json). Allow them if an IP allowlist sits in front of Flashduty
* If `description` contains a double quote, the rendered JSON is invalid and the request is rejected as a parameter error

## Troubleshooting

***

* **Flashduty receives nothing**: confirm the webhook destination is complete, includes `integration_key`, and the integration is enabled
* **Parameter error**: a missing `notification.id` means the template dropped `id`; an invalid JSON message means a string field is not quoted
* **Alerts never close**: UpGuard sends no recovery notification, so turn on the channel's auto-close

For more information, see [UpGuard's webhook integration guide](https://help.upguard.com/en/articles/4205928-how-to-integrate-upguard-with-other-services-using-webhooks).
