A webhook reverses the usual API pattern. Instead of your system repeatedly asking "anything new?", the source system sends an HTTP POST to a URL you register the moment something happens — an alert fires, an asset moves.
Why it matters
Webhooks connect asset events to the rest of your stack: open a ticket when a zone-exit alert fires, post to a chat channel, update an ERP record when an asset moves.
Securing webhooks
| Control | Purpose |
|---|---|
| Signature (e.g. HMAC) | Proves the payload came from the sender and was not altered |
| Timestamp check | Rejects old, replayed deliveries |
| HTTPS only | Protects data in transit |
| Idempotent handling | Safe if the same event is delivered twice |
In Asetavo
Asetavo delivers alerts and movement events through signed, SSRF-safe webhooks (Business plan), so your systems can verify each delivery and react in real time.