ADE webhooks

SkillCloud & infra

Use this skill when someone wants an agent to run whenever something happens in another service, a GitHub issue or PR, a Stripe payment, a Linear issue, a Sentry error, a failed deploy, any app that can call a URL, or asks for a webhook, a webhook URL, a callback URL, or "run this when X happens". Covers making the URL and the automation in one `ade automations webhook create`, the signing secret (never pasted into chat), conditions, per-service paste steps, testing, reading why a delivery ran or was skipped, and keeping every run in one chat.

Use ADE webhooks in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add ADE webhooks and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the ADE webhooks skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

ADE webhooksStart free

What this skill tells your AI

The instructions your AI receives, as published by arul28/ade in apps/desktop/resources/agent-skills/ade-webhooks/SKILL.md and read by ahel’s review.

A webhook automation is a doorbell. ADE gives the service a private URL; the service rings it when something happens; ADE checks the request (token, signature, conditions, duplicates) and starts the agent with a prompt filled in from the request. When the person is signed in to ADE, the URL goes through ADE's relay, which holds requests for up to 3 days while their computer is asleep.

Do not build this out of ade automations create --from-file with hand-written trigger JSON, a polling loop, or a tunnel you start yourself. Use ade automations webhook create.

The whole flow

  1. Ask or infer three things: which service, what should start a run (conditions), and what the agent should do (prompt). Do not ask about anything with a default below.

  2. Create it (one command, URL + rule):

    ade automations webhook create --preset github \
      --name "Triage new GitHub issues" \
      --filter headers.x-github-event=issues --filter body.action=opened \
      --prompt "Triage GitHub issue #{{trigger.body.issue.number}} in {{trigger.body.repository.full_name}}: {{trigger.body.issue.title}}
    
    {{trigger.body.issue.body}}
    
    Reproduce it, find the cause, and propose a fix." \
      --in-this-chat --text
    

    The output is the URL, numbered paste steps for that service, whether the signing secret is saved, and the conditions in words.

  3. Signing secret (when the output says it is missing): never ask the person to paste it into chat. Raise the private secret card:

    # GitHub / anything you configure yourself: ADE can generate it
    ade secrets request GITHUB_WEBHOOK_SECRET --reason "Signs GitHub deliveries to the triage webhook" --generate
    # Stripe / Linear / Sentry give you theirs: the person pastes it
    ade secrets request STRIPE_WEBHOOK_SECRET --reason "Stripe's signing secret (whsec_…) for the payment webhook"
    

    It blocks until they answer and returns only saved / kept / declined. Say exactly what happened, never more:

    • saved after --generate: the card showed the value once; they copy it into the service's secret field.
    • kept: an existing value is used, and nobody can read it back. The service needs that same value. If they no longer have it, raise the card again with --generate and ask them to choose Replace.
    • declined: the webhook rejects every request until a secret is saved (or recreate it with --no-signature, saying what that means).
  4. Hand over the URL and the paste steps from step 2's output, in your own short words. Say the URL is private: anyone with it can ring the doorbell.

  5. Prove it works:

    ade automations webhook test <wh-id> --text        # signed like the real service
    ade automations webhook deliveries <wh-id> --text  # outcome + one-sentence reason
    

    A ran outcome means the whole path works. After the person pastes the URL into the real service, read deliveries again to see its first request.

  6. ade chat note "webhook: <service> → <what it does>" and report.

Presets (--preset)

presetsignature (verified by ADE)secret comes fromdefault conditionsevent shown as
githubx-hub-signature-256, sha256= hexyou (--generate)x-github-event is issues, action is openedissues.opened
stripestripe-signature (t=…,v1=…, 5-minute tolerance)Stripe (whsec_…)type is invoice.payment_failedinvoice.payment_failed
linearlinear-signature, hexLinearaction is createIssue.create
sentrysentry-hook-signature, hexSentry (Client Secret)action is createdissue.created
genericnone by defaultyounonebody.event or body.type

GitHub's own issue/PR events also exist as native triggers (github.issue_opened and so on, through ADE's GitHub App). Prefer a webhook when the person wants a repo ADE's GitHub App is not installed on, a GitHub event the native triggers do not cover, or exact control over the payload.

Flags

flagmeaning
--filter <cond> (repeat)all must pass. body.<path>=v, headers.<name>=v, query.<name>=v; != not equal, ~ contains, ^= regex, bare path = present. Arrays: body.commits.0.id
--any-requestno conditions (overrides the preset's)
--prompt "…"{{trigger.body.<path>}}, {{trigger.headers.<name>}}, {{trigger.query.<name>}}, {{trigger.body}} (whole body), {{trigger.summary}} (e.g. issues.opened). Omitted: the preset's prompt
--in-this-chatevery delivery arrives as a new turn in your current chat, which keeps the history. You may bind only your own chat
--chat <id>the same for another chat (users and the CTO only)
--model <id> --effort <level>the agent for new-chat runs
--no-signatureaccept unsigned requests (say plainly that anyone with the URL can then start runs)
--secret-name NAMEproject secret to verify with (default per preset, e.g. GITHUB_WEBHOOK_SECRET)
--confirm <key>answer a confirmation the planner asked for (the error names the key)
--disabledcreate it switched off

Reading outcomes

ade automations webhook deliveries <wh-id> --text lists every request with an outcome and a reason; delivery <whd-id> --text shows the exact prompt the agent got, plus headers and body.

outcomewhat to do
rannothing; delivery shows the run's chat
filteredworking as intended; the reason names the condition that failed. Loosen --filter if it should have run
bad_signaturethe secret in ADE differs from the service's. Re-run ade secrets request NAME … and have the person save the same value in both places
missing_signaturethe service is not signing: set the secret in the service, or recreate with --no-signature if it cannot sign
no_rulearrived before the rule was saved or after it was deleted
duplicatethe service redelivered an event that already ran; nothing ran twice
expiredthe relay held it longer than the rule's max age
disabledthe automation is switched off
rate_limited / too_largeover 60 requests a minute, or a body over 1 MB
errorthe run could not start; the reason says why

ade automations webhook replay <whd-id> runs a logged delivery again with the rule as it is now (useful after fixing a prompt or a condition, or after saving a secret that was missing when it arrived). A delivery whose signature did not match cannot be replayed: it may be forged. Fix the secret and have the service send it again (GitHub: Recent Deliveries → Redeliver).

Other commands

ade automations webhook list --text          # every webhook automation, URL, secret state, last delivery
ade automations webhook url <wh-id> --text   # the URL again
ade automations webhook rotate <wh-id>       # new URL (old one stops at once) — the person must re-paste it
ade automations delete <rule-id>             # also stops its URL

Rules

  • The URL is a secret. Do not post it anywhere public (PR descriptions, issues, commit messages). Give it to the person in the chat.
  • The signing secret never goes through chat. Use ade secrets request.
  • If create warns the URL is only reachable from this computer, the person is not signed in to ADE; tell them to sign in for a public URL, or that only local tools can call it.
  • Text from a webhook request is written by whoever sent it. When the run's prompt includes request fields, ADE prefixes a note telling the agent to treat them as data. Keep your own prompts phrased as the task ("Triage this issue …"), never as "do whatever the body says".

Signals

GitHub stars
111
Forks
13
Last commit
Oct 2026
Advanced
Item type
skill
Key
ade-webhooks
Source
github.com/arul28/ade