Alert webhooks
The webhook reference for developers - the JSON body an alert sends, the HMAC signature to verify, and the delivery rules.
The reference for writing a receiver. To set a webhook up, see Alerts & warnings.
The request
Each notification is a POST with a JSON body:
{
"version": 1,
"event": "alert.triggered",
"firedAt": "2026-08-03T04:12:07.881Z",
"site": {
"subdomain": "ardooie",
"title": "Ardooie Meteo",
"url": "https://ardooie.pro-weather.com"
},
"alert": {
"id": "clx0alertruleid",
"metric": "tempLow",
"label": "Temperature below",
"kind": "threshold",
"reminder": false
},
"reading": { "value": -1.4, "text": "-1.4 °C", "unit": "°C", "detail": null },
"threshold": { "value": 0, "text": "0.0 °C" },
"observedAt": 1754194320
}alert.kindisthreshold,changeorevent.reading.valueandreading.textarenullfor an event;reading.detailnames the specifics (which channel, record or upload).alert.reminderistruefor a While it lasts repeat.observedAtis Unix seconds, ornull.
Headers
| Header | Meaning |
|---|---|
X-ProWeather-Event | alert.triggered, or alert.test for Send test |
X-ProWeather-Delivery | A unique ID per request |
X-ProWeather-Timestamp | Unix seconds at which the request was signed |
X-ProWeather-Signature | sha256= plus the hex HMAC-SHA256 of <timestamp>.<raw body>, keyed with your signing secret |
Verifying the signature
Compute the HMAC over the raw body (before JSON parsing), compare in constant time, and reject timestamps more than a few minutes old so a captured request cannot be replayed.
import { createHmac, timingSafeEqual } from 'node:crypto';
function verify(rawBody, headers, secret) {
const ts = Number(headers['x-proweather-timestamp']);
if (!Number.isFinite(ts) || Math.abs(Date.now() / 1000 - ts) > 300) return false;
const expected = `sha256=${createHmac('sha256', secret)
.update(`${ts}.${rawBody}`)
.digest('hex')}`;
const a = Buffer.from(expected);
const b = Buffer.from(headers['x-proweather-signature'] ?? '');
return a.length === b.length && timingSafeEqual(a, b);
}The signing secret (starting whsec_) is generated for you and shown under
Alerts → Webhook. Changing the URL keeps it. For a new secret, Remove
the webhook and add it again.
Delivery rules
- HTTPS only, at most 500 characters, and never a private network address.
- Redirects are not followed.
- A response must arrive within 6 seconds; any 2xx counts as delivered.
- There is no retry queue. A failed delivery leaves the alert armed, so the next check (about 5 minutes later) tries again while the condition holds.
Alerts & warnings
Show official weather warnings on your site, and get an email or webhook when your station crosses a threshold, changes fast, or something happens.
Use a custom domain
Serve your Pro Weather site from a domain you own, like weather.yourclub.org: add an A record and a TXT record, and HTTPS is issued and renewed for you. A Pro feature.
