GitHub webhook receiver
const url = 'https://api.aletheia-ops.com/api/v1/webhooks/github';const options = {method: 'POST'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.aletheia-ops.com/api/v1/webhooks/githubResponses
Section titled “Responses”Accepted
Fast-ack webhook response body
object
Examplegenerated
{ "status": "example"}The request is malformed or fails validation.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "validation_failed", "message": "name: must not be blank"}{ "code": "invalid_state", "message": "invalid or expired install state"}{ "code": "unsafe_base_url", "message": "base URL is not permitted"}{ "code": "invalid_body", "message": "could not read request body"}No valid credential was presented, or it has expired.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "unauthorized", "message": "authentication required"}{ "code": "invalid_credentials", "message": "invalid email or password"}{ "code": "invalid_token", "message": "invalid or expired token"}{ "code": "token_reuse", "message": "session revoked"}{ "code": "webhook_unauthorized", "message": "webhook verification failed"}Authenticated, but not permitted to perform this action.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "forbidden", "message": "you do not have permission to perform this action"}{ "code": "csrf_failed", "message": "missing or invalid CSRF token"}{ "code": "account_deactivated", "message": "your account is deactivated; contact your administrator"}{ "code": "ai_disabled", "message": "the AI assistant is disabled for this organization"}The request conflicts with the current state.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "email_taken", "message": "an account with this email already exists"}{ "code": "slug_taken", "message": "organization slug already taken"}{ "code": "name_taken", "message": "a connection with this name already exists"}{ "code": "account_exists", "message": "this AWS account is already connected"}{ "code": "connection_exists", "message": "a connection for this organization already exists"}{ "code": "scan_conflict", "message": "an equivalent scan is already queued or running"}{ "code": "invitation_invalid", "message": "this invitation is no longer valid"}{ "code": "last_admin", "message": "the organization must keep at least one active platform administrator"}{ "code": "conflict", "message": "a resource with this identifier already exists"}{ "code": "turn_in_progress", "message": "a turn is already in progress on this conversation"}The request body exceeds the configured limit. Terraform plans are capped
by CRITIAS_INGEST_MAX_PLAN_BYTES (32 MiB by default); webhook bodies
have their own limit.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "payload_too_large", "message": "plan exceeds CRITIAS_INGEST_MAX_PLAN_BYTES"}An unexpected failure. Diagnostic detail is logged server-side and
deliberately not returned. Quote the X-Request-Id response header when
reporting one.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "internal_error", "message": "internal server error"}