Skip to main content
This guide includes features awaiting release. If an option is not available in your workspace, contact StackShift Support.

What you can do

Connect your own systems with explicit permissions and observable delivery. Where to find it: Settings → Integrations → Developer and Credentials

Before you start

  • Integration management permission and a developer maintaining the receiving system.
  • An HTTPS webhook destination you control when using webhooks.

Steps

1
Create a scoped credential for the intended workspace and environment. Save its one-time secret in protected server configuration; choose the smallest permissions your integration needs.
2
For outgoing events, create a webhook with the desired events and destination. Implement the documented signature verification before acting on received data.
3
Send a webhook test and inspect delivery history. Handle duplicate delivery safely and distinguish retryable failures from a successful action whose response was lost.
4
For a custom app, use Developer to configure installation consent, registered actions, execution grants and signing keys as applicable. Test within its granted scope.
5
Rotate credentials and signing keys through their controls, update the receiving application and verify operation before retiring old access. Revoke integrations no longer needed.

Example

A webhook notifies your internal system that a ticket changed; the receiver verifies the signature and processes an event only once.

Things to know

  • Public widget keys do not replace server API credentials.
  • API clients should retain the same Idempotency-Key and original payload for an uncertain retry; revision-protected changes need the current If-Match value.
  • Custom actions require an explicit execution grant; registering an app does not authorize arbitrary business operations.

What happens next

Your integration has a known scope and a way to inspect failed deliveries or action outcomes.

If something goes wrong

  • Permission denied: compare credential scope and current workspace/inbox authority.
  • Webhook failed: inspect response status and signature verification; do not expose signing secrets in logs.
  • Stale revision: reload the current record, review changes and submit again.

Connect business tools to Support

Bring useful customer context and approved actions into conversations.

Support organizations and permissions

Group workspaces, invite staff and grant only the access each person needs.