Webhooks let you deliver Cloudflare alerts to any service that accepts HTTP callbacks. You can connect to popular services like Slack, Google Chat, and PagerDuty, or configure a generic webhook for any custom endpoint.
-
In the Cloudflare dashboard, go to Alerts > Destinations.
Go to Alerts ↗ -
In the Webhooks card, select Create.
-
Give your webhook a name.
-
In the URL field, enter the webhook URL for the service you want to connect.
-
If needed, enter the Secret. Secrets vary by service — refer to popular webhook services for details.
-
Select Save and Test to finish setting up your webhook.
You can rename or delete existing webhooks.
-
In the Cloudflare dashboard, go to Alerts > Destinations.
Go to Alerts ↗ -
In the Webhooks card, select Edit on the webhook you want to modify.
-
Update the name and select Save, or select Delete to remove it.
Webhook alerts are sent from Cloudflare's IP ranges ↗︎. If your webhook endpoint is protected by a firewall, you must allowlist these IP addresses to receive alerts.
To programmatically retrieve the current list of Cloudflare IP addresses, use the Cloudflare API.
If you use a service that is not covered by Cloudflare's currently available webhooks, you can configure your own, and enter a valid webhook URL.
It is always recommended to use a secret for generic webhooks. Cloudflare will send your secret in the cf-webhook-auth header of every request made. If this header is not present, or is not your specified value, you should reject the webhook.
When Cloudflare sends a webhook alert, the payload has the following schema:
{
"text": "Hello World! This is a test message sent from https://cloudflare.com. If you can see this, your webhook is configured properly."
}For the full payload structure and examples, refer to the webhook payload schema reference.
Generic webhook alerts will only be dispatched to a publicly resolvable IP address on port 80 or 443.
If you want to receive alerts on a private IP address or different port, you can either receive and forward them using Workers or set up a Cloudflare Tunnel to route to your connected application.
You can use Cloudflare Workers with a generic webhook to deliver alerts to any service that accepts webhooks.
Cloudflare has an example tool ↗︎ that shows how to use Workers to transform a generic webhook payload for delivery to Rocket.Chat. The code is heavily commented to help you adapt it to your needs.
For Google Chat ↗︎:
- Secret: The secret is part of the URL. Cloudflare parses this information automatically and there is no input needed from the user.
- URL: URL varies depending on the Google Chat channel's address.
For Slack ↗︎:
- Secret: The secret is part of the URL. Cloudflare parses this information automatically and there is no input needed from the user.
- URL: URL varies depending on the Slack channel's address.
For DataDog ↗︎:
- Secret: The secret is required and has to be entered by the user. This is what DataDog refers to as API Key ↗︎
- URL:
https://api.datadoghq.com/api/v1/events
For Discord ↗︎:
- Secret: The secret is part of the URL. Cloudflare parses this information automatically and there is no input needed from the user.
- URL: URL varies depending on the Discord channel's address.
For OpsGenie ↗︎:
- Secret: The secret is the
API Keyfor OpsGenie's REST API. - URL:
https://api.opsgenie.com/v2/alerts
For Splunk ↗︎:
- Secret: The secret is required and has to be entered by the user. This is what Splunk refers to as
token. Refer to Splunk’s documentation ↗︎ for details. - URL:
- We only support three Splunk endpoints: services/collector, services/collector/raw, and services/collector/event.
- If SSL is enabled on the token, the port must be 443. If SSL is not enabled on the token, the port must be 8088.
- SSL must be enabled on the server.
- Enable indexer acknowledgement must be disabled on the Splunk HTTP Event Collector.
For Feishu ↗︎:
- Secret: The secret is part of the URL. Cloudflare parses this information automatically and there is no input needed from the user.
- URL: The URL varies depending on the Custom Robot.
For Teams ↗︎:
- Secret: The secret is part of the URL. Cloudflare parses this information automatically and there is no input needed from the user.
- URL: URL is provided by Teams when the Incoming Webhook connector is created.
For ServiceNow ↗︎:
- Secret: User decides. Ensure that the secret entered in Cloudflare matches what is configured in ServiceNow. Refer to ServiceNow's documentation ↗︎ for details.
- URL:
https://{servicenow_instance}.com/{base_api_path}
For a Generic webhook:
- Secret: User decides.
- URL: User decides.
For Google Chat, Slack, Discord, and Feishu webhooks, the secret is embedded in the URL and extracted automatically. You can instead remove the secret from the URL and set it explicitly, which is useful when managing webhooks as infrastructure-as-code with Terraform.
resource "cloudflare_notification_policy_webhooks" "example" {
account_id = "<ACCOUNT_ID>"
name = "Slack Webhook"
url = "https://hooks.slack.com/services/T00000000/B00000000"
secret = "<secret>"
}