Prerequisites
The connector should already be set up, with a Connector Profile and a Linked Account. See Getting Started on the GitLab connector page.Connect GitLab webhooks
GitLab sends events to StackOne through a webhook added in each project. Paste the StackOne Native Webhook URL into a new project webhook and select the triggers you want to receive.
Retrieve StackOne Native Webhook URL
The Native Webhook URL is generated once an account has been linked.
- Open the linked account in StackOne.
- Copy the value from Native Webhook URL.
Open the project webhook settings
Sign in to your GitLab account and open the project you want to receive events from.
- In the left sidebar, select Settings > Webhooks.

Add a new webhook
On the Webhooks page, click Add new webhook.

Paste the Native Webhook URL
Fill in the webhook details.
- Name (optional): enter a name such as
StackOne. - URL: paste the StackOne Native Webhook URL.
- Leave Signing token and Secret token (not recommended) empty. StackOne does not verify them.

Select the triggers
Under Trigger, tick the events you want StackOne to receive. See Available webhook events below for the events each trigger sends.
- For Push events, keep All branches selected to receive pushes to every branch.

Save the webhook
Keep Enable SSL verification ticked and click Add webhook.

Test the webhook
GitLab shows Webhook created and lists the new webhook. Use the Test menu on the webhook to send a sample event for a trigger and confirm that it reaches StackOne.

Available webhook events
The following GitLab events are supported. GitLab only sends the events whose trigger is ticked on the webhook, and StackOne only delivers the events you enable in StackOne.
Code events
Events for pushes and tags. Enable Push events and Tag push events.
- Push (
push) — Fired when commits are pushed to a branch of a project - Tag Push (
tag_push) — Fired when a tag is created or deleted in a project
Work item and issue events
Events for issues and other work items. Enable Work item events (and Confidential work items events for confidential ones).
- Issue Opened (
issue.open) — Fired when an issue is opened in a project - Issue Closed (
issue.close) — Fired when an issue is closed in a project - Issue Reopened (
issue.reopen) — Fired when an issue is reopened in a project - Issue Updated (
issue.update) — Fired when an issue is edited in a project - Work Item Opened (
work_item.open) — Fired when a work item such as a task or epic is opened - Work Item Closed (
work_item.close) — Fired when a work item such as a task or epic is closed - Work Item Reopened (
work_item.reopen) — Fired when a work item such as a task or epic is reopened - Work Item Updated (
work_item.update) — Fired when a work item such as a task or epic is edited
Merge request events
Events for the merge request lifecycle and approvals. Enable Merge request events.
- Merge Request Opened (
merge_request.open) — Fired when a merge request is opened - Merge Request Closed (
merge_request.close) — Fired when a merge request is closed without merging - Merge Request Reopened (
merge_request.reopen) — Fired when a merge request is reopened - Merge Request Updated (
merge_request.update) — Fired when a merge request is updated - Merge Request Merged (
merge_request.merge) — Fired when a merge request is merged - Merge Request Approval Added (
merge_request.approval) — Fired when a merge request is approved by one approver - Merge Request Approved (
merge_request.approved) — Fired when a merge request is fully approved - Merge Request Approval Removed (
merge_request.unapproval) — Fired when a merge request is unapproved by one approver - Merge Request Unapproved (
merge_request.unapproved) — Fired when a merge request is no longer fully approved
Comment and reaction events
Events for comments and emoji reactions. Enable Comments, Confidential comments and Emoji events.
- Comment Created (
note.create) — Fired when a comment is created on a commit, merge request, issue or snippet - Comment Updated (
note.update) — Fired when a comment is updated on a commit, merge request, issue or snippet - Emoji Reaction Awarded (
emoji.award) — Fired when an emoji reaction is added to an issue, merge request, snippet or comment - Emoji Reaction Revoked (
emoji.revoke) — Fired when an emoji reaction is removed from an issue, merge request, snippet or comment
CI/CD and deployment events
Events for pipelines, jobs, deployments and feature flags. Enable Pipeline events, Job events, Deployment events and Feature flag events.
- Pipeline Status Changed (
pipeline) — Fired when a pipeline is created or its status changes - Job Status Changed (
build) — Fired when a CI/CD job is created or its status changes - Deployment Status Changed (
deployment) — Fired when a deployment starts, succeeds, fails, is canceled or is approved or rejected - Feature Flag Toggled (
feature_flag) — Fired when a feature flag is turned on or off
Release, milestone and wiki events
Events for releases, milestones and wiki pages. Enable Releases events, Milestone events and Wiki page events.
- Release Created (
release.create) — Fired when a release is created in a project - Release Updated (
release.update) — Fired when a release is updated in a project - Release Deleted (
release.delete) — Fired when a release is deleted in a project - Milestone Created (
milestone.create) — Fired when a project milestone is created - Milestone Closed (
milestone.close) — Fired when a project milestone is closed - Milestone Reopened (
milestone.reopen) — Fired when a project milestone is reopened - Milestone Deleted (
milestone.delete) — Fired when a project milestone is deleted - Wiki Page Created (
wiki_page.create) — Fired when a project wiki page is created - Wiki Page Updated (
wiki_page.update) — Fired when a project wiki page is updated - Wiki Page Deleted (
wiki_page.delete) — Fired when a project wiki page is deleted
Security events
Events for expiring access tokens and vulnerabilities. Enable Resource access token events and Vulnerability events (Ultimate only).
- Access Token Expiring (
access_token.expiring_access_token) — Fired when a project or group access token is about to expire - Vulnerability Created or Updated (
vulnerability) — Fired when a vulnerability is created or its state or details change
Group-only events
Sent only by group webhooks (GitLab Premium or Ultimate), on the group’s Settings > Webhooks page.
- Group Member Added (
user_add_to_group) — Fired when a user is added to the group - Group Member Updated (
user_update_for_group) — Fired when a group member access level or expiry changes - Group Member Removed (
user_remove_from_group) — Fired when a user is removed from the group - Group Access Requested (
user_access_request_to_group) — Fired when a user requests access to the group - Group Access Request Denied (
user_access_request_denied_for_group) — Fired when a group access request is denied - Group Project Created (
project_create) — Fired when a project is created in the group - Group Project Deleted (
project_destroy) — Fired when a project is deleted in the group - Subgroup Created (
subgroup_create) — Fired when a subgroup is created in the group - Subgroup Deleted (
subgroup_destroy) — Fired when a subgroup is deleted in the group
Delivery format
Details of how GitLab delivers events to StackOne.
One event per request
Each request carries a single JSON event. GitLab retries a delivery that times out, so the same event can arrive more than once. Each event carries the ID of the affected record (for example the issue IID or the pipeline ID).
Failing deliveries disable the webhook
GitLab marks a webhook as temporarily disabled after 4 consecutive failed deliveries and disables it after 40. StackOne answers every delivery with 200, including event types it does not handle, so the webhook stays enabled.