Do not publish the URL
Avoid placing webhook URLs in public GitHub repos, screenshots, browser JavaScript, forum posts, or support tickets unless specifically requested.
Security
A webhook URL is a direct address for sending alerts to a Space. Keep it private and use it only in systems you trust.
Avoid placing webhook URLs in public GitHub repos, screenshots, browser JavaScript, forum posts, or support tickets unless specifically requested.
Do not send passwords, payment card data, full private records, or unnecessary personal details. Send only what someone needs to act on the alert.
Use WordPress webhooks, backend code, n8n, Zapier, Make, or a same-origin proxy so the webhook URL is not visible to every website visitor.
If a webhook URL is accidentally shared, replace it in the connected system and stop using the exposed URL.
Anyone who has your PINGSLAP webhook URL can send notifications directly into that Space. Treat the URL like an API secret token or password.
.env file is a familiar example, but the literal filename is not required—many hosting platforms and cloud providers provide native environment variable settings or secrets managers..env file on your server, make sure your web server is configured to block public downloads of dotfiles, and add .env to your .gitignore so it is never pushed to version control. The security property comes from keeping the secret strictly server-side and preventing public access, not from automatic encryption.{
"title": "New lead",
"message": "Call Taylor today",
"leadId": "CRM-1042"
}Link to the full record inside your CRM or admin tool instead of sending all details in the notification payload.