PIERRE COMPUTER COMPANY █
CODE STORAGE
2026
← Back
------
Feature:

Webhook Custom Headers

Date:October 05, 2026Author:Sean LingrenCategory:ENGINEERING
------

Webhook subscriptions can now send custom headers with every delivery. Use them to authenticate requests at your endpoint or to attach routing metadata, such as Authorization: Bearer <token> or X-Environment: production.

Add headers in the webhook editor in the dashboard. Code Storage sends them next to its own headers:

POST /hooks/code-storage HTTP/1.1
Content-Type: application/json
User-Agent: Pierre-Webhook/1.0
X-Pierre-Event: push
X-Pierre-Signature: t=1790197200,sha256=...
Authorization: Bearer <token>
X-Environment: production

Each subscription supports up to 10 custom headers and 8 KiB total, and requires an HTTPS endpoint. Values are encrypted at rest. After you save, the dashboard shows only header names. A saved value stays masked until you replace or remove it. Changing the webhook URL keeps the saved headers.

Pierre's own headers and connection, proxy, and trace headers are reserved. This includes X-Pierre*, Host, Content-*, X-Forwarded-*, and Traceparent. Custom headers do not change signature verification, which still covers the timestamp and the request body.

Each delivery captures the subscription configuration before its first attempt. Retries keep the headers they started with. Edits apply to deliveries that start after the change.

  • The webhooks list is now a table. Click a row to open that webhook's delivery history. Each row shows whether the webhook is active or inactive.
  • The editor lets you choose events: push, repo.sync.started, repo.sync.succeeded, and repo.sync.failed. Before, the dashboard subscribed every webhook to push only.
  • Headers stay collapsed until you add one. Removing a saved header asks for confirmation.

Code Storage also rejects webhook URLs that it cannot deliver to, such as localhost, URLs without a scheme, and private IP addresses. Code Storage does not follow redirects, and a 3xx response now ends a delivery instead of causing retries.

See the docs →

+ Recently +