Webhooks
Webhooks Webhooks send exposures to your own systems — a SIEM, a ticketing tool, a chat channel, an automation — the moment they happen. FathomWatch POSTs a signed JSON message to your URL for each event you subscribe to. Webhooks are part of the Organization plan. Anyone in the organization can manage its webhooks. Create a webhook Open Webhooks in the sidebar (in your organization's context). Enter a label, the destination URL, the leak type to send (or All types) and the events. Select Add webhook. The signing secret is shown once — store it in your receiver's configuration. If you lose it, delete the webhook and create a new one. Select Send test to send a test event, and check Last delivery for the result. The URL must be http or https and reachable from the internet: addresses that resolve to private, loopback or link-local networks are refused. Use https. Events Event Sent when new_leak A new exposure arrives (credentials not reported before). status_changed Someone changes an exposure's status. recurrence_seen Credentials that were already reported turn up again in new data. test You select Send test. Request Every message has these fields, plus the event's own: Field Type Description event string new_leak, status_changed, recurrence_seen or test. occurred_at string When FathomWatch sent it (RFC 3339, UTC). org_id string Your organization's ID. new_leak Field Description leak.id The exposure's ID — stable across status_changed and recurrence_seen. leak.url Link to the exposure in FathomWatch (sign-in required). leak.credential_count Credentials stored for this part of the exposure. leak.part, leak.parts Large exposures are split into parts of up to 2,000 credentials; each part is its own new_leak. credentials[].account The affected account, in full. credentials[].url The site the login was saved for. credentials[].password_masked The first few characters of the password, then ••••••. The full password is never sent or stored. credentials[].sha1 Uppercase hex SHA-1 of the password, to check it against public breached-password lists without revealing it. status_changed Statuses are new, investigating, resolved and dismissed. note is empty when none was given; actor is the email of the person who made the change. recurrence_seen recurrences is how many already-reported credentials were seen again. No credentials are included: you already received them in a new_leak. test Verify the signature X-FathomWatch-Signature is sha256= followed by the hex HMAC-SHA256 of the raw request body, keyed with your signing secret (used as-is, as text — don't decode it). Read the raw body before parsing it as JSON. Compute the HMAC and compare it with the header in constant time. Reject anything that doesn't match with 401. Working receivers in Python, Go and Node.js: Webhook examples. Delivery Answer with any 2xx within 10 seconds. Do slow work after answering. On a timeout, a network error or a non-2xx answer, FathomWatch tries up to 3 times (waiting 1 second, then 2). After the third failure the message is dropped and Last delivery shows the failure. A retry resends the identical body, so you may receive the same message more than once: use a hash of the body to ignore duplicates. Messages can arrive in any order. Use leak.id to tie events about the same exposure together. Don't rely on webhooks as your only record: the leak inbox and Export CSV always have everything.
FathomWatch documentation