Skip to main content
This page documents the webhook events and payload fields relevant to Entri Secure. For the payload envelope and signature verification, see Webhooks Overview.

Webhook event types

Entri Secure sends its own webhook events, in addition to the Secure fields it adds to the standard flow payload described below.
These events are only delivered if they are selected for your application in the Dashboard, under Application → Webhooks, in the Webhook events section. See Choosing which events you receive.

domain.secure.provisioned

Sent when a security certificate is successfully issued for a domain and it’s ready to serve visitors safely. Use it to confirm the domain is protected and let your user know everything is in place. It tells you which domain was secured and when it happened.

domain.secure.deprovisioned

Sent when Secure is removed from a domain and Entri stops managing its certificate. Use it to close things out on your side or let the affected user know their domain is no longer covered. It tells you which domain was removed and when it happened.

domain.secure.certificate_renewal_failed

Sent when a certificate managed by Secure can’t be renewed because the domain’s settings are missing something or pointing to the wrong place. Use it to alert the domain owner early, before their certificate lapses and visitors run into security warnings. It tells you which domain is affected, when the renewal failed, what the settings should look like, and what they currently look like, so the owner knows exactly what to fix.
For a domain set up on a root domain, expected_records contains the A records Secure expects. For any other domain it contains a single CNAME record pointing at your cname_target.

Status fields

  • secure_status: Only relevant when using Entri Secure. Describes the status of SSL security configuration. Possible values:
    • "pending": SSL configuration is pending.
    • "success": SSL setup was successful.
    • "failed": SSL setup failed.
    • "exempt": Entri Secure does not apply to the current flow.
In the domain.secure.* events listed above, secure_status reports whether Secure is currently running on the domain and uses a different set of values: "active" or "inactive". The values above apply to the standard flow payload.

Payload fields

  • cname_target: Only applicable for Entri Power and Secure setups. The CNAME target used for DNS configuration (e.g. "my.saascompany.com").