Skip to main content

General

Keep URLs Private

Your webhook URLs are like passwords. ❌ Don’t:
  • Commit to git repositories
  • Paste in Slack/Discord
  • Share via email
  • Post in public forums
✅ Do:
  • Store in environment variables
  • Use secrets manager (1Password, AWS Secrets, etc.)
  • Only share with trusted teammates
  • Rotate if accidentally exposed

Generate Unique API Keys Per Integration

Don’t reuse the same API key everywhere. ✅ Better approach:
  • API key for GitHub → github-ci
  • API key for Stripe → stripe-payments
  • API key for Zapier → zapier-automations
Benefits:
  • Revoke one without breaking others
  • Track which integration is sending requests
  • Easier to audit and rotate keys

Implement Retry Logic

Not all requests will succeed first try.

Catch and Log Errors

Always handle failures gracefully.

Webhooks

Use Template Variables

Don’t duplicate data in title and body. ❌ Don’t:
✅ Do:

Test Webhooks Before Production

Most services let you send test webhooks.
  1. Send test event from service
  2. Check it appears in Dashtray history
  3. Verify data is correct
  4. Configure template
  5. Then enable in production

Set Appropriate Frequency

Don’t notify for every single event. ❌ Too noisy:
  • Every page view
  • Every log line
  • Every API call
✅ Good frequency:
  • Errors/failures
  • Completed tasks
  • State changes
  • Important milestones

Handle High-Volume Services

If service sends many events: Option 1: Filter at source
  • Only send certain events
  • Use service’s filters/rules
  • Reduce payload size
Option 2: Multiple alerts
  • Create separate alerts for different triggers
  • Route based on event type
  • Better organization
Option 3: Batch notifications
  • Collect events, send summary
  • Example: “5 deployments completed”
  • Less noisy

Protect Your Webhook URL

The webhook URL itself is the credential — anyone with it can send to your phone. Treat it like a password:
  • Keep it secret - Don’t commit it to repos or share it publicly
  • Rotate on exposure - If a URL leaks, rotate it from the alert page; the old code stops working immediately
  • The code is the auth - There is no separate signing secret; the unguessable short code protects the endpoint

Respond Quickly

Acknowledge the webhook immediately, process async:

Rate Limiting

Plan Ahead

Know your plan’s limits:

Monitor Usage

Check your stats regularly:
  • Settings → API Stats
  • See requests per minute
  • Watch for approaching limits

Handle Rate Limits Gracefully

Optimize Requests

Avoid unnecessary calls: ❌ Inefficient:
  • Calling API for every event
  • Sending duplicate notifications
  • Polling instead of webhooks
✅ Efficient:
  • Batch similar notifications
  • Use webhooks (they push to you)
  • Only send when necessary

Security

Rotate Keys Regularly

Best practice: rotate API keys quarterly Steps:
  1. Generate new API key
  2. Update all places using old key
  3. Test everything works
  4. Revoke old key

Never Log API Keys

Use Environment Variables

Validate Input

Always sanitize webhook payloads:

Performance

Batch Notifications

Don’t send 100 individual notifications. Send summaries: ❌ 100 separate requests:
✅ One request:

Cache Results

Don’t recalculate if you already sent:

Don’t Spam in Quiet Hours

Respect user’s quiet hours setting:

Monitoring

Track Delivery

Monitor successful vs failed notifications:

Alert on Failures

Set up alerts if notification delivery fails:

Use Structured Logging

Log in structured format for analysis:

Common Pitfalls to Avoid

❌ Mistake: Blocking on notification
✅ Better: Fire and forget

❌ Mistake: Hardcoding tokens
✅ Better: Use environment variables

❌ Mistake: No error handling
✅ Better: Catch errors

Summary Checklist

Before going to production:
  • ✅ Validate all inputs
  • ✅ Implement retry logic
  • ✅ Use unique API keys
  • ✅ Store secrets in environment variables
  • ✅ Verify webhook signatures
  • ✅ Log errors but not secrets
  • ✅ Test with real data
  • ✅ Monitor delivery rates
  • ✅ Handle rate limits gracefully
  • ✅ Respect quiet hours
Ready to deploy! 🚀