General
Keep URLs Private
Your webhook URLs are like passwords. ❌ Don’t:- Commit to git repositories
- Paste in Slack/Discord
- Share via email
- Post in public forums
- Store in environment variables
- Use secrets manager (1Password, AWS Secrets, etc.)
- Only share with trusted teammates
- Rotate if accidentally exposed
Generate Unique API Keys Per Integration
Don’t reuse the same API key everywhere. ✅ Better approach:- API key for GitHub →
github-ci - API key for Stripe →
stripe-payments - API key for Zapier →
zapier-automations
- Revoke one without breaking others
- Track which integration is sending requests
- Easier to audit and rotate keys
Implement Retry Logic
Not all requests will succeed first try.Catch and Log Errors
Always handle failures gracefully.Webhooks
Use Template Variables
Don’t duplicate data in title and body. ❌ Don’t:Test Webhooks Before Production
Most services let you send test webhooks.- Send test event from service
- Check it appears in Dashtray history
- Verify data is correct
- Configure template
- Then enable in production
Set Appropriate Frequency
Don’t notify for every single event. ❌ Too noisy:- Every page view
- Every log line
- Every API call
- Errors/failures
- Completed tasks
- State changes
- Important milestones
Handle High-Volume Services
If service sends many events: Option 1: Filter at source- Only send certain events
- Use service’s filters/rules
- Reduce payload size
- Create separate alerts for different triggers
- Route based on event type
- Better organization
- Collect events, send summary
- Example: “5 deployments completed”
- Less noisy
Protect Your Webhook URL
The webhook URL itself is the credential — anyone with it can send to your phone. Treat it like a password:- Keep it secret - Don’t commit it to repos or share it publicly
- Rotate on exposure - If a URL leaks, rotate it from the alert page; the old code stops working immediately
- The code is the auth - There is no separate signing secret; the unguessable short code protects the endpoint
Respond Quickly
Acknowledge the webhook immediately, process async:Rate Limiting
Plan Ahead
Know your plan’s limits:Monitor Usage
Check your stats regularly:- Settings → API Stats
- See requests per minute
- Watch for approaching limits
Handle Rate Limits Gracefully
Optimize Requests
Avoid unnecessary calls: ❌ Inefficient:- Calling API for every event
- Sending duplicate notifications
- Polling instead of webhooks
- Batch similar notifications
- Use webhooks (they push to you)
- Only send when necessary
Security
Rotate Keys Regularly
Best practice: rotate API keys quarterly Steps:- Generate new API key
- Update all places using old key
- Test everything works
- Revoke old key
Never Log API Keys
Use Environment Variables
Validate Input
Always sanitize webhook payloads:Performance
Batch Notifications
Don’t send 100 individual notifications. Send summaries: ❌ 100 separate requests:Cache Results
Don’t recalculate if you already sent:Don’t Spam in Quiet Hours
Respect user’s quiet hours setting:Monitoring
Track Delivery
Monitor successful vs failed notifications:Alert on Failures
Set up alerts if notification delivery fails:Use Structured Logging
Log in structured format for analysis:Common Pitfalls to Avoid
❌ Mistake: Blocking on notification❌ Mistake: Hardcoding tokens
❌ Mistake: No error handling
Summary Checklist
Before going to production:- ✅ Validate all inputs
- ✅ Implement retry logic
- ✅ Use unique API keys
- ✅ Store secrets in environment variables
- ✅ Verify webhook signatures
- ✅ Log errors but not secrets
- ✅ Test with real data
- ✅ Monitor delivery rates
- ✅ Handle rate limits gracefully
- ✅ Respect quiet hours