FerryDocs
ArchitectureSecurity model

Deploy hook keys

A deploy hook has its own key in its URL. The key can start a deploy and nothing else.

Edit on GitHub
Your CIDeploy hook/hooks/deploy/…New deploy

A request with the correct key starts a deploy. It can do nothing else.

1 / 3
The URL of a deploy hook
/hooks/deploy/<service id>?key=<key>

Webhooks do not use the account or an API token. Each one has its own secret. For a , the secret is the key in the URL.

The path takes the service id only, because names are easy to guess.

The URL is a password

Each person who has the URL can start deploys of the service, but nothing else.

If the URL leaks

Replace the key:

Terminal
ferry deploy-hook rotate NAME

Deploy hooks shows how to use a hook. The API overview has the details.

On this page