Security

Treat webhook URLs like passwords.

A webhook URL is a direct address for sending alerts to a Space. Keep it private and use it only in systems you trust.

Do not publish the URL

Avoid placing webhook URLs in public GitHub repos, screenshots, browser JavaScript, forum posts, or support tickets unless specifically requested.

Avoid sensitive information

Do not send passwords, payment card data, full private records, or unnecessary personal details. Send only what someone needs to act on the alert.

Prefer server-side sending

Use WordPress webhooks, backend code, n8n, Zapier, Make, or a same-origin proxy so the webhook URL is not visible to every website visitor.

Rotate if exposed

If a webhook URL is accidentally shared, replace it in the connected system and stop using the exposed URL.

Treat your webhook URL like a secret

Anyone who has your PINGSLAP webhook URL can send notifications directly into that Space. Treat the URL like an API secret token or password.

  • Keep it out of public code: Do not embed webhook URLs in frontend JavaScript, insert them into public HTML forms, commit them to public GitHub repositories, or expose them in screenshots or video tutorials.
  • Use server-side environment configuration: Keep the webhook URL in server-side environment or secret configuration rather than client-accessible files. A .env file is a familiar example, but the literal filename is not required—many hosting platforms and cloud providers provide native environment variable settings or secrets managers.
  • Protect configuration files from public downloads: If you use a .env file on your server, make sure your web server is configured to block public downloads of dotfiles, and add .env to your .gitignore so it is never pushed to version control. The security property comes from keeping the secret strictly server-side and preventing public access, not from automatic encryption.
  • Direct server-to-server systems: Backend applications, automation platforms (n8n, Zapier, Make), and server-side WordPress plugins already execute on private servers. Because they never ship the webhook URL to visitors' browsers, they can send directly to PINGSLAP without needing an extra proxy layer.

Safer alert shape

{
  "title": "New lead",
  "message": "Call Taylor today",
  "leadId": "CRM-1042"
}

Link to the full record inside your CRM or admin tool instead of sending all details in the notification payload.