Pro Weather.

Alert webhooks

The webhook reference for developers - the JSON body an alert sends, the HMAC signature to verify, and the delivery rules.

The reference for writing a receiver. To set a webhook up, see Alerts & warnings.

The request

Each notification is a POST with a JSON body:

{
  "version": 1,
  "event": "alert.triggered",
  "firedAt": "2026-08-03T04:12:07.881Z",
  "site": {
    "subdomain": "ardooie",
    "title": "Ardooie Meteo",
    "url": "https://ardooie.pro-weather.com"
  },
  "alert": {
    "id": "clx0alertruleid",
    "metric": "tempLow",
    "label": "Temperature below",
    "kind": "threshold",
    "reminder": false
  },
  "reading": { "value": -1.4, "text": "-1.4 °C", "unit": "°C", "detail": null },
  "threshold": { "value": 0, "text": "0.0 °C" },
  "observedAt": 1754194320
}
  • alert.kind is threshold, change or event.
  • reading.value and reading.text are null for an event; reading.detail names the specifics (which channel, record or upload).
  • alert.reminder is true for a While it lasts repeat.
  • observedAt is Unix seconds, or null.

Headers

HeaderMeaning
X-ProWeather-Eventalert.triggered, or alert.test for Send test
X-ProWeather-DeliveryA unique ID per request
X-ProWeather-TimestampUnix seconds at which the request was signed
X-ProWeather-Signaturesha256= plus the hex HMAC-SHA256 of <timestamp>.<raw body>, keyed with your signing secret

Verifying the signature

Compute the HMAC over the raw body (before JSON parsing), compare in constant time, and reject timestamps more than a few minutes old so a captured request cannot be replayed.

import { createHmac, timingSafeEqual } from 'node:crypto';

function verify(rawBody, headers, secret) {
  const ts = Number(headers['x-proweather-timestamp']);
  if (!Number.isFinite(ts) || Math.abs(Date.now() / 1000 - ts) > 300) return false;
  const expected = `sha256=${createHmac('sha256', secret)
    .update(`${ts}.${rawBody}`)
    .digest('hex')}`;
  const a = Buffer.from(expected);
  const b = Buffer.from(headers['x-proweather-signature'] ?? '');
  return a.length === b.length && timingSafeEqual(a, b);
}

The signing secret (starting whsec_) is generated for you and shown under Alerts → Webhook. Changing the URL keeps it. For a new secret, Remove the webhook and add it again.

Delivery rules

  • HTTPS only, at most 500 characters, and never a private network address.
  • Redirects are not followed.
  • A response must arrive within 6 seconds; any 2xx counts as delivered.
  • There is no retry queue. A failed delivery leaves the alert armed, so the next check (about 5 minutes later) tries again while the condition holds.

On this page