Skip to main content

Prerequisites

The connector should already be set up, with a Connector Profile and a Linked Account. See Getting Started on the Snyk connector page.

How webhooks are set up

Snyk delivers events through an organization-scoped webhook subscription, and StackOne provisions it for you on connection. When you connect your account, StackOne creates one Snyk webhook (POST /v1/org/{orgId}/webhooks) pointing at a StackOne callback URL. When you disconnect, StackOne deletes that webhook (DELETE /v1/org/{orgId}/webhooks/{id}). There is nothing to configure in Snyk.

1

Set your Organization ID

Because Snyk webhooks are organization-scoped, provide the Organization ID of the Snyk organization you want events from. Find it in Snyk under the organization’s Settings > General > Organization ID.

2

Connect with your token

Authorize the connection with your Snyk Auth Token (or Personal Access Token) and Region so StackOne can create and delete the webhook subscription on your behalf. Creating outbound webhooks requires an Enterprise plan and an organization role with the outbound-webhook permissions.

Available webhook events

Snyk delivers a single webhook event type. StackOne routes each delivery to its handler.

1

Project events

Events related to project tests and snapshots.

  • Project Snapshot (project_snapshot) — Fired every time an existing project is tested and a new snapshot is created, whether or not there are new issues. Applies to Open Source and Container projects, which Snyk re-tests on a recurring schedule.

Delivery format

Details of how Snyk delivers events to StackOne.

1

Headers carry the metadata

Each delivery is a single JSON object whose body holds project, org, group, newIssues, and removedIssues. The event type, a unique delivery id, and the timestamp travel in the X-Snyk-Event, X-Snyk-Transport-ID, and X-Snyk-Timestamp headers, which StackOne maps to the event type, id, and date.

2

Signature

Snyk signs every delivery with an X-Hub-Signature header (an HMAC-SHA256 digest of the request body using the subscription secret). StackOne routes each delivery to its matching event handler.

Verify

Your Connector should now be able to receive and process events. Try triggering an event and you should see an Event appear in the Connector logs.