Integrations
Alert source integrations for on-call: 136 catalogued sources, one pipeline.
Each catalogued source has its own payload mapping and setup page, built and tested against sample payloads for that source’s webhook format.
136 sources
- AirbrakeairbrakeError notification webhook (new/occurring errors).
- AppDynamicsappdynamicsAlert & Respond HTTP Request Action (policy violations).
- Aqua SecurityaquaImage scan & runtime policy alerts via webhook.
- Argo CDargocdNotifications webhook (health Degraded / sync OutOfSync).
- Atlassian BamboobambooBuild notification recipient (Failed/Unknown).
- Atlassian StatuspagestatuspageIncoming incident / component update webhooks.
- Auth0auth0Log Streams webhook — tenant auth events (failed logins, blocks).
- AWS CloudTrailcloudtrailCloudTrail API activity via EventBridge → webhook.
- AWS CloudWatchcloudwatchCloudWatch alarm state changes, via an EventBridge rule you create in your own AWS account.
- AWS CloudWatch Alarm (via SNS)cloudwatchalarmCloudWatch alarm published to SNS → HTTPS subscription.
- AWS ConfigawsconfigConfig rule compliance changes via EventBridge → webhook.
- AWS GuardDutyguarddutyGuardDuty findings via EventBridge → webhook (API destination).
- AWS HealthawshealthAWS Health events via EventBridge → webhook.
- AWS InspectorawsinspectorAmazon Inspector v2 findings via EventBridge → webhook.
- AWS MacieawsmacieAmazon Macie sensitive-data findings via EventBridge → webhook.
- AWS Security HubsecurityhubSecurity Hub findings (ASFF) via EventBridge → webhook.
- Azure DevOpsazuredevopsService Hooks web hook (build/pipeline events).
- Azure MonitorazuremonitorAlerts via action group webhook (Common Alert Schema).
- Better StackbetterstackBetter Stack Uptime incident webhook.
- Bitbucket PipelinesbitbucketpipelinesRepository webhook (build status / pipeline events).
- BugSnagbugsnagError events via the data-forwarding webhook.
- CatchpointcatchpointSynthetic-monitoring alert webhook (Warning/Critical).
- ChecklychecklySynthetic & API monitoring — check failures and degradations.
- CheckmkcheckmkWebhook notification script POSTing state context macros.
- ChronospherechronosphereObservability platform — Prometheus-compatible notifier webhook.
- CircleCIcircleciworkflow-completed webhook (CI workflow conclusions).
- Cisco MerakimerakiDashboard alert webhook (critical/warning/informational).
- Cisco ThousandEyesthousandeyesNetwork-intelligence & synthetic alert webhook (ACTIVE).
- CloudflarecloudflareNotifications webhook (health checks, DoS, SSL, etc.).
- CodefreshcodefreshPipeline build webhook (error/terminated).
- CoralogixcoralogixAlert webhook (Critical/Error/Warning/Info).
- CronitorcronitorCron job & uptime monitoring — alert and recovery notifications.
- CrowdStrike FalconcrowdstrikeEndpoint security — Falcon detection summary events.
- DatadogdatadogMonitors & events via Datadog webhook integration.
- DynatracedynatraceProblem notifications via a custom integration webhook.
- Elastic / KibanaelasticKibana alerting webhook connector (ELK rule alerts).
- FalcofalcoRuntime-security detection via falcosidekick webhook.
- Fastly Next-Gen WAFfastlySignal Sciences NGWAF site alerts & flags via webhook.
- FireHydrantfirehydrantIncident management — incident created and updated webhooks.
- Flux CDfluxcdnotification-controller generic webhook (info/error events).
- FreshpingfreshpingFreshworks uptime monitoring — alert webhook.
- FreshservicefreshserviceITSM ticket events via Workflow Automator webhook.
- GCP Security Command CentersecuritycommandcenterGCP Security Command Center findings, posted as {finding:{...}} JSON by a small relay you build that unwraps the Pub/Sub push envelope.
- Generic webhookgenericAny tool — post our canonical alert JSON directly.
- GitHub Actionsgithubactionsworkflow_run webhook for CI run conclusions.
- GitHub DependabotdependabotDependabot vulnerability alerts via the repo webhook.
- GitLab CIgitlabciPipeline Events webhook for CI pipeline outcomes.
- Google Cloud MonitoringgcpmonitoringAlert policy webhook notification channel.
- GrafanagrafanaGrafana unified alerting contact point (8+) and legacy.
- Grafana LokilokiLoki ruler alerts via Alertmanager-shaped webhook.
- Grafana MimirmimirMimir Alertmanager pointed directly at CallHeim.
- Grafana OnCallgrafanaoncallGrafana OnCall outgoing/formatted webhook (alert groups).
- Graphite (Seyren)graphiteSeyren / graphite-beacon check webhook (ERROR/WARN/OK).
- GrayloggraylogLog management — alerts & events HTTP Notification.
- HarnessharnessPipeline notification webhook (FAILED/EXPIRED).
- Healthchecks.iohealthchecksioCron / heartbeat monitoring — fires when a check goes down.
- HetrixToolshetrixtoolsUptime & blacklist monitoring webhooks.
- HoneybadgerhoneybadgerFault notification webhook.
- HoneycombhoneycombHoneycomb Triggers webhook (TRIGGERED/OK).
- IBM InstanainstanaGeneric webhook alert channel (issues/incidents).
- Icinga 2icingaNotification command POSTing host/service state macros.
- incident.ioincidentioIncident management — incident created/updated webhooks.
- InfluxDB / KapacitorinfluxdbKapacitor HTTPPost / InfluxDB check alert webhook.
- IntercomintercomConversation notification webhooks (priority/state changes).
- JenkinsjenkinsCI build outcome via the Notification plugin webhook.
- JetBrains TeamCityteamcityBuild webhook (tcWebHooks) (failure/running/success).
- KentikkentikAlerting / DDoS notification webhook (critical/major/minor).
- Kubernetes EventskuberneteseventsCluster events via kubernetes-event-exporter webhook (Warning→P2).
- LaceworklaceworkAlert channel webhook (numeric/string severity 1..5).
- LibreNMSlibrenmsNetwork monitoring — critical/warning alert transport.
- LogglylogglySolarWinds Loggly — saved-search threshold alert webhooks.
- LogicMonitorlogicmonitorAlert integration webhook (critical/error/warn).
- LogRocketlogrocketSession replay & front-end error alerts via webhook.
- Logz.iologzioAlert notification endpoint (custom webhook).
- MackerelmackerelHost & service monitoring — critical/warning alert transitions.
- Mailgun (inbound email)mailgunSend Mailgun alert mail to your workspace’s own inbound alert address (Trial, Business or Enterprise plan), or route it through a generic webhook integration.
- Mezmo (LogDNA)mezmoLog view/alert webhook (level → severity).
- Microsoft SentinelazuresentinelSentinel incidents via automation rule / Logic App webhook.
- MoogsoftmoogsoftAIOps alerts/situations via an outbound webhook.
- NagiosnagiosNotification command POSTing host/service state macros.
- NetdatanetdataAlarm notification webhook (CRITICAL/WARNING/CLEAR).
- New RelicnewrelicAlerts / Workflows webhook (incidents & issues).
- Octopus DeployoctopusdeploySubscription webhook (DeploymentFailed/Succeeded).
- Oh DearohdearUptime, certificate & broken-link monitoring — typed events.
- OktaoktaOkta Event Hooks reach CallHeim through a relay you run, which answers Okta’s one-time verification request.
- OpenTelemetry / CloudEventsopentelemetryCloudEvents 1.0 structured-mode JSON events (Knative, Azure Event Grid, or your own CloudEvents producer). This is not an OpenTelemetry (OTLP) receiver.
- OpsgenieopsgenieOutgoing webhook integration (alert create).
- Orca SecurityorcaCloud-security alert webhook (severity / score 1..10).
- Paessler PRTGprtgNotification HTTP action (Down/Warning).
- PagerDutypagerdutyV3 webhook subscription (incident triggered).
- PagerDuty Events API (compatible)pagerdutyeventsAccepts PagerDuty Events API v2 and legacy v1 request bodies at your CallHeim URL, for tools that let you set the Events API endpoint. CallHeim includes a payload mapping for PagerDuty's Events API format.
- PagerTreepagertreeOn-call alerting — outbound alert lifecycle webhooks.
- PapertrailpapertrailSaved-search alert webhook (log events).
- PingdompingdomUptime/transaction check webhook (state change).
- Postmark (inbound email)postmarkSend Postmark alert mail to your workspace’s own inbound alert address (Trial, Business or Enterprise plan), or route it through a generic webhook integration.
- Prisma CloudprismacloudPalo Alto Prisma Cloud alert webhook (critical/high/medium/low).
- Prometheus AlertmanagerprometheusAlertmanager webhook receiver (firing/resolved groups).
- Prometheus Alertmanager (direct)alertmanagerAlertmanager pointed straight at CallHeim (no Prometheus relay).
- QualysqualysVMDR detection webhook (severity 1..5, 5 = highest).
- RaygunraygunCrash Reporting webhook (grouped errors).
- RollbarrollbarItem alerts via the legacy webhook notification.
- RootlyrootlyIncident management — incident lifecycle webhooks (SEV0..SEV4).
- RunscoperunscopeAPI monitoring — test-run pass/fail result webhooks.
- SematextsematextAlert notification webhook (critical/warning/info).
- SemgrepsemgrepAppSec findings webhook (high/medium/low).
- SendGrid (inbound email)sendgridSend SendGrid alert mail to your workspace’s own inbound alert address (Trial, Business or Enterprise plan), or route it through a generic webhook integration.
- Sensu GosensuHandler webhook (check.status 0/1/2/3 → severity).
- SentinelOnesentineloneEndpoint security — threat detection & mitigation webhooks.
- SentrysentryIssue alerts via Sentry internal integration / legacy webhook.
- ServiceNowservicenowEvent Management events / ITSM incidents via webhook.
- Site24x7site24x7Monitor status webhook (Down/Trouble).
- SnyksnykNew-vulnerabilities webhook (critical/high/medium/low).
- SolarWinds OrionsolarwindsOrion/Observability alert action POST (Critical/Serious/Warning).
- SonarQubesonarqubeQuality Gate webhook (OK / ERROR after analysis).
- SpinnakerspinnakerEcho pipeline notification webhook (TERMINAL/SUCCEEDED).
- SplunksplunkSaved-search webhook alert action.
- Splunk Observability (SignalFx)signalfxDetector alert webhook (Critical/Major/Minor/Warning/Info).
- Splunk On-Call (VictorOps)victoropsIncident alerting — REST endpoint message_type transitions.
- SquadcastsquadcastIncident response — triggered/acknowledged/resolved events with priority.
- StatusCakestatuscakeUptime test state-change webhook.
- Sumo LogicsumologicMonitor alert webhook connection (Critical/Warning).
- SysdigsysdigMonitor/Secure notification webhook (events).
- TenabletenableTenable.io / Security Center finding webhook (critical/high/medium).
- ThanosthanosThanos Ruler alerts via the Alertmanager-compatible webhook.
- Travis CItravisciBuild notification webhook (Passed/Failed/Errored).
- TrivytrivyContainer/IaC vulnerability scan reports via webhook.
- updown.ioupdownUptime & SSL monitoring — check status-change webhooks.
- Uptime KumauptimekumaSelf-hosted uptime monitoring — heartbeat webhooks.
- UptimeRobotuptimerobotUptime monitor webhook alert contact (Down).
- VictoriaMetrics (vmalert)victoriametricsvmalert Alertmanager-shaped webhook pointed directly at us.
- Wavefront (Aria Operations)wavefrontAlert target webhook (SEVERE/WARN/INFO).
- WazuhwazuhOpen-source SIEM/XDR — rule-level security alert forwarding.
- WizwizCloud-security Issues webhook (CRITICAL/HIGH/MEDIUM/LOW).
- ZabbixzabbixZabbix webhook media type (problem).
- ZendeskzendeskSupport ticket events via trigger + webhook.
- ZendutyzendutyIncident response — outbound alert webhooks.
By category
Where the coverage is.
- Security25
- Metrics & monitoring24
- Incident & ITSM18
- CI/CD & deployment16
- Uptime & synthetics15
- Logging10
- Cloud platforms9
- APM & tracing7
- Error tracking7
- Email ingest3
- Generic webhook2
136 sources across 11 categories. Security is the largest, which is why security operations gets its own page.
How ingest works
Create an Integration and CallHeim shows you its ingest URL. CallHeim verifies an HMAC-SHA256 signature on each source’s requests once you enable signing on that integration (the sending tool must be able to sign). Without a signing secret, the URL itself is the credential — a URL cannot be rotated, so disable the integration to revoke a source. The endpoint enqueues and returns; the processor drains the queue.
If your tool is not listed
The generic webhook accepts any JSON object, and a no-code mapping (dot and bracket paths) picks out the fields that matter. PagerDuty Events API v2 and legacy v1 bodies are also accepted as-is, so a tool that lets you set its Events API endpoint can often be repointed rather than rebuilt.
If it only sends email
Trial, Business and Enterprise plans: each workspace gets an inbound alert e-mail address for email-to-alert; mail sent to it becomes an alert. Starter and Pro do not include it. Available in early access.
Put a rule you can read between your alerts and your on-call.
CallHeim helps teams stay in control when critical systems are not. Explore the platform, connect one source, and send yourself a page.
Early access · every workspace starts with a 14-day trial for up to 5 seats, no card required