FerryDocs
ArchitectureSecurity model

GitHub webhooks

GitHub signs each delivery with a shared secret. Ferry refuses a bad signature and ignores a copy.

Edit on GitHub
signatureGitHubsigns the bodyFerry404A copyan old delivery

With no --github-webhook-secret, the endpoint answers 404.

1 / 4

A GitHub does not use the account or an API token. Its proof is an signature made with the .

The rules

RuleDetail
Off by defaultThe endpoint answers 404 until you set --github-webhook-secret.
SignatureX-Hub-Signature-256: HMAC-SHA256 of the raw body, compared in .
No Ferry ignores a delivery if it processed the same body or the same delivery id before.

Turn it on

On the server
ferryd --github-webhook-secret <secret>

Give the same secret to GitHub. GitHub auto-deploy shows each step. The API overview has the details.

On this page