Signed news alerts for a persistent AI agent
By Blake Folgado · Updated 2026-10-03
An MCP connection lets an assistant read alerts when it asks. A webhook sends an event to a persistent receiver you control. Use a webhook when an agent runtime or service needs to react after the original chat has ended.
The receiver needs a public HTTPS URL, secure secret storage, deduplication and a way to process events after acknowledging the request. Choose the monitor and destination explicitly before connecting.
The workflow
- Inspect the monitor and current delivery settings.
- Review the callback URL and authorise delivery.connect with platform webhook, webhook_url and monitor_id.
- Store the returned signing_secret in the receiver secret store.
- Verify each request, acknowledge promptly with 2xx and process asynchronously.
- Inspect delivery status and use alerts.list to recover missed events.
sentrydock delivery connect --platform webhook --webhook-url https://your-agent.example/alerts --monitor MONITOR_IDVerify the signed request
Compute HMAC-SHA256 with the signing secret over X-SentryDock-Timestamp + a dot + the unchanged raw request body. Compare against X-SentryDock-Signature using a constant-time comparison. Reject timestamps older than five minutes and deduplicate the event ID before triggering work.
Do not parse and re-serialise the JSON before verifying the signature: that changes the bytes being authenticated. Keep the secret outside logs, prompts and shared files.
Example agent task
“Inspect my named monitor and delivery. Propose connecting it to the HTTPS callback I provide. Show the monitor ID and destination before changing anything. After I approve, connect it, store the returned signing secret securely and tell me what receiver checks are still required.”
What proves delivery?
A saved destination proves configuration. A monitor result proves a run produced output. A successful webhook attempt proves the receiver accepted that request; processing by the downstream agent needs its own receipt. Inspect delivery status before assuming an event arrived.
Retries are bounded. Use alerts.list to reconcile missing events and deduplicate replayed IDs. Do not repeatedly create delivery destinations after an uncertain response.
Reference and plan requirements
Webhook protocol and delivery rules · Current API schema · Monitor failures.
Monitor scheduling and news access follow the account plan. Creating a callback does not start a background process inside a chat-only client.