| name | webhook-subscriptions |
| description | Use when external services should trigger agent runs through webhook events |
Webhook Subscriptions
Overview
Webhook-triggered agents are powerful because they turn external events into work. Treat every webhook as an untrusted public input unless proven otherwise.
Setup Pattern
- Confirm the gateway or webhook receiver is available.
- Generate a strong per-subscription secret outside the repo.
- Subscribe to the smallest event set that solves the task.
- Test with a synthetic payload.
- Log only event metadata, not secret headers or private payload fields.
Example Shape
hermes webhook subscribe repo-issues \
--events "issues" \
--prompt "Triage this issue event and propose next steps." \
--skills "github-issues,github-code-review"
Verification
hermes webhook list
hermes webhook test repo-issues --payload '{"action":"opened"}'
Safety
- Require HMAC validation or an equivalent signature check.
- Keep webhook secrets in environment variables or a private config file.
- Do not commit event payloads from production systems.
- Prefer dry-run delivery until the prompt is proven safe.