Webhook examples
Webhook examples Three small, working receivers for FathomWatch webhooks: Python, Go and Node.js, each using only its standard library. Each one: verifies X-FathomWatch-Signature against the raw body, in constant time, and answers 401 if it doesn't match; answers 204 straight away, then handles the event; ignores repeated deliveries of the same message; prints a line for each event — replace handle with your own automation (open a ticket, page someone, call your SIEM). Run one behind HTTPS (a reverse proxy or your platform's load balancer) at a URL FathomWatch can reach, then point a webhook at it and select Send test. [!NOTE] The duplicate check keeps fingerprints in memory, so it forgets them on restart. In production, store them in your database or Redis with an expiry of a day or so. Python Python 3.9 or newer. Set CHAT_WEBHOOK_URL to a Slack or Microsoft Teams incoming-webhook URL to post every new exposure to a channel as well. Go Go 1.21 or newer. Node.js Node.js 18 or newer. Test without FathomWatch Sign a sample message yourself and send it to your receiver: Expect HTTP/1.1 204. Change one character of the body or the secret and you should get 401.
FathomWatch documentation