Email and webhook alerts
Send incident notifications by email or signed webhook, and check every delivery. Pro and Integrator.
How alerts work
OpticWatch sends a notification when an incident opens and when it is resolved. You choose where notifications go by adding destinations under Alerts: email addresses, webhook URLs, or both. Every enabled destination receives both events.
Email alerts
Email needs two things: the mail server OpticWatch sends through, and at least one email destination.
Configure the mail server
Open Settings and find Email. Use the SMTP details from your email provider or IT team.
- Send alerts by email
- The switch for all email delivery. When off, email destinations stay configured but nothing is sent.
- Mail server
- The SMTP server's hostname only, without a port, for example smtp.example.com.
- Security
- STARTTLS (usually port 587), TLS (usually port 465), or None (unencrypted).
- Port
- The server's SMTP port.
- From address
- The sender of the alerts. Your mail server may require an address it owns.
- Username and Password
- Optional. Leave both empty if your server does not require sign-in. A saved password is never shown again; leave the field empty to keep it.
Send a test message
Under Send a test message, enter your address and send it. If it does not arrive, check the server details and your spam folder.
Add an email destination
Open Alerts, choose Add destination, give it a name such as “Operations on-call”, choose the email type and enter the Recipient email. Add one destination per recipient.
Each alert email names the camera and site, says whether the camera is OFFLINE or RECOVERED, and gives the start time, the reason, and, once resolved, the end time and duration.
Webhook alerts
A webhook sends each notification as an HTTP request to a URL you choose, so you can connect OpticWatch to your own systems: a ticketing tool, a chat bridge, or an automation platform. OpticWatch has no built-in Slack, Teams or PagerDuty integrations; a webhook is how you connect to those yourself.
Add a webhook destination
Open Alerts, choose Add destination, and choose the webhook type.
- Name
- How the destination appears in OpticWatch.
- Webhook URL
- Where to send requests: an http:// or https:// address, for example https://example.com/hooks/opticwatch. Use https:// for anything beyond your own network.
- Signing secret
- A secret string you choose, shared with the receiver so it can verify requests came from OpticWatch. Optional but strongly recommended. It cannot be viewed after saving; leave it empty when editing to keep it.
- Send notifications to this destination
- On by default. Turn off to keep the destination without sending to it.
Send a test
Choose Test next to the destination. OpticWatch sends a test request and shows whether your receiver accepted it.
What OpticWatch sends
Each notification is a POST request with a JSON body. The receiver must answer with an HTTP status from 200 to 299 within 10 seconds for the delivery to count as successful.
X-OpticWatch-EventINCIDENT_OPENEDorINCIDENT_RESOLVED(orTESTfor a test).X-OpticWatch-Delivery- An identifier for this notification. Retries of the same notification repeat it.
X-OpticWatch-Timestamp- When the request was sent, in Unix seconds.
X-OpticWatch-Signature- Present when the destination has a signing secret:
sha256=followed by a hex signature.
An incident notification looks like this (identifiers and names invented):
{
"event": "INCIDENT_OPENED",
"occurred_at": "2026-10-05T19:44:03.481294+00:00",
"incident": {
"id": "5f0c2a7e-1b9d-4c3e-8a61-2f4d7b9e0c13",
"status": "OPEN",
"started_at": "2026-10-05T19:44:03.402118+00:00",
"resolved_at": null,
"reason": "The camera could not be reached.",
"duration_seconds": null
},
"camera": { "id": "8d3e6f21-7c4a-4b0e-9f15-6a2c8e1d4b70", "name": "Loading dock, east" },
"site": { "id": "2b7a9c04-3e5f-4d18-a6c2-9e0f1b3d5a87", "name": "Northgate warehouse" }
}For INCIDENT_RESOLVED, status is RESOLVED and resolved_at and duration_seconds are filled in. A test request carries event, occurred_at and a message only.
Verifying the signature
The signature is an HMAC-SHA256, keyed with your signing secret, over the timestamp header, a period, and the raw request body. To check a request, the receiver:
- Takes the
X-OpticWatch-Timestampvalue and the request body exactly as received, before any JSON parsing. - Computes HMAC-SHA256 with the signing secret over
timestamp + "." + body, and writes it as lowercase hex. - Compares
sha256=plus that hex value withX-OpticWatch-Signature, using a constant-time comparison, and rejects the request if they differ. - Optionally rejects requests whose timestamp is far from the current time, so an old request cannot be replayed later.
Retries and delivery history
If a delivery fails, OpticWatch tries again after 1, 5, 15 and 60 minutes: five attempts in all, then it marks the delivery as failed.
Alerts lists Recent deliveries: every notification attempt, including retries, with its event, camera, destination, number of attempts, time of the last attempt and any error. Filter it by destination, by status (Delivered, Retrying or Failed) and by event. Delivery history is kept indefinitely, even after a destination is deleted.