Security

Send Snyk alerts to on-call with CallHeim.

New-vulnerabilities webhook (critical/high/medium/low). CallHeim maps the payload, collapses repeats within five minutes, and pages whoever is on call for the service it belongs to.

snykSnyk

Setting it up

Register a webhook via the Snyk Webhooks API to receive project_snapshot/new-issue events.

Create an Integration in CallHeim and choose Snyk from the Catalog. You get an ingest URL for that integration — paste it into Snyk’s webhook configuration. The snippet beside this is the shape it expects, with {{WEBHOOK_URL}} replaced by your real URL.

Snyk signs its webhooks with its own header, which CallHeim does not verify. Do not enable a signing secret for this integration — every delivery would then be rejected. The ingest URL itself is the credential.

CallHeim includes a payload mapping for Snyk’s webhook format, built and tested against sample payloads.

Snyk webhook documentation →

Setup snippetsnyk
# Register a Snyk webhook (Webhooks API):
curl -X POST https://api.snyk.io/v1/org/<ORG_ID>/webhooks \
  -H 'authorization: token <SNYK_TOKEN>' -H 'content-type: application/json' \
  -d '{"url":"{{WEBHOOK_URL}}","secret":"<secret>"}'
Example shape written by us; check Snyk’s current documentation.

After it arrives

What CallHeim does with Snyk alerts.

Detection alerts are the case where sending content to an external model is least acceptable. Severity and correlation for these alerts are computed by rule-based code inside our own AWS environment; no finding is sent to an external AI model. An optional Amazon Bedrock path exists in the code and is switched off.

CallHeim maps Snyk’s own severity to a P1–P5 level and shows a separate, explainable severity suggestion — a published keyword ruleset plus your own resolved-incident history — that a person can apply. How severity is suggested →

Each alert source is bound to a service, and the service’s escalation policy (or its team’s) sets who is paged. Alerting and escalation →

CallHeim closes an incident on a recovery event only for sources whose recovery payload it recognises (or that you map). For the others, a person resolves the incident.

The thresholds it passes through

Dedup window
300s
Flap threshold
4 transitions / 600s
Title correlation
similarity ≥ 0.6, same source and service
Group window default
600s

All defaults are published. You can turn title correlation off or change its threshold, and set the window on your own noise rules; the dedup window and the flap settings are fixed. How alerts are processed →

CallHeim

Point Snyk at CallHeim and see what it does with your alerts.

Explore the platform, connect one source, and send yourself a test page by e-mail (early access).

Early access · every workspace starts with a 14-day trial for up to 5 seats, no card required