API reference · Trust Fabric
Get notified when an action is held, blocked or halted
POST /fabric/webhooks
Last reviewed 2026-10-03
POST /fabric/webhooks
Register a URL to notify.
The URL is resolved and every address it answers with is checked before the endpoint is accepted, and again before every delivery attempt. A webhook is a request this server makes on your instruction; an unvalidated one is server-side request forgery with extra steps.
Request body
WebhookRequest (required)
| Field | Type | Meaning |
|---|---|---|
url required | string | min length 8 · max length 2000 |
events | array of string | |
description | string or null | max length 200 |
format | string | cain (signed JSON envelope), splunk_hec or xsiam default "cain" |
auth_token | string or null | the SIEM collector's token (splunk_hec, xsiam); stored, never returned max length 512 |
Responses
| Status | Meaning | Body |
|---|---|---|
200 | Successful Response | JSON |
422 | Validation Error | HTTPValidationError |
401 | No key, or a key that is not valid | JSON detail |
429 | Rate limit for your plan reached; retry after the Retry-After seconds | JSON detail |
Try it
This call changes data in the account the key belongs to.
The request goes from your browser straight to this site. Your key is not stored unless you tick the box, and then only in this tab's session storage.
Code
curl -sS -X POST 'https://cainstudio.online/fabric/webhooks' \
-H "X-API-Key: $CAIN_API_KEY" \
-H 'Content-Type: application/json' \
-d '{"url": "url", "format": "cain"}'import json, os, urllib.request
req = urllib.request.Request('https://cainstudio.online/fabric/webhooks', method='POST',
headers={"X-API-Key": os.environ["CAIN_API_KEY"], "Content-Type": "application/json"},
data=json.dumps({
"url": "url",
"format": "cain"
}).encode())
with urllib.request.urlopen(req, timeout=60) as r:
print(r.status, json.load(r))const res = await fetch("https://cainstudio.online/fabric/webhooks", {
method: "POST",
headers: {
"X-API-Key": process.env.CAIN_API_KEY!,
"Content-Type": "application/json",
},
body: JSON.stringify({
"url": "url",
"format": "cain"
}),
});
console.log(res.status, await res.json());Schemas used
HTTPValidationError · ValidationError · WebhookRequest
← Where this tenant gets notified · all 79 Trust Fabric calls · What was sent, and what failed →
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem