📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Compliance API & Webhooks

Connect your compliance data to other systems: give them an API token to read controls, risks and evidence, and send events to Slack, Teams or your own endpoint as they happen.

Where to find it
Compliance › API & Webhooks (from the compliance section's own navigation or the console search)
Who can use it
GRC administrators
Plan
Compliance (GRC) platform
For
Everyone

What the page is for

API tokens let another system, such as a ticketing tool or reporting dashboard, read this company's compliance data or create tasks and link evidence. Each token has scopes that limit what it can do and expires after at most a year. A token is shown once, when it is created.

Webhooks send an HTTPS message to an address you choose whenever a selected compliance event happens. Slack and Microsoft Teams incoming-webhook addresses get a short text message; any other address gets a signed JSON document. Failed deliveries are retried automatically, and every delivery is logged.

A third tab, Using the API, documents the requests and shows how to verify a webhook's signature.

What you see

The Compliance API & Webhooks page, with the tabs, new token / new webhook, tokens and webhooks tables and webhook editor numbered 1 to 4.
The Compliance API & Webhooks page. Numbers match the list below.
  1. Tabs: API tokens, Webhooks and Using the API.
  2. New token / New webhook: the add button at the top of each tab.
  3. Tokens and webhooks tables: API tokens: Name, Token (prefix only), Scopes, Created, Last used, Expires, State and Revoke. Webhooks: Address (masked), Format, Events, Last delivery, Waiting, State, with Test, Log (the delivery log, with Retry) and More (Edit address or events, Switch off or on, Rotate secret, Delete).
  4. Webhook editor: Address (https) and Events, with Select all.

How to use Compliance API & Webhooks

How to create an API token

  1. On API tokens, select New token.
  2. Enter a Name that says what uses it, for example "Ticketing system sync".
  3. Choose Scopes. read is ticked by default; add write:tasks or write:evidence only if needed.
  4. Choose Expires after: 30 days, 90 days (default), 180 days or 1 year (the maximum).
  5. Select Create token, then copy it. Select I have copied it when done; it will not be shown again.

How to revoke a token

  1. Select Revoke on the token's row and confirm. Anything using it stops working at once.

How to send compliance events to Slack or Teams

  1. On Webhooks, select New webhook.
  2. Paste the Slack or Teams incoming-webhook address into Address (https).
  3. Tick the Events you want, or Select all.
  4. Select Save and copy the signing secret shown once.
  5. Select Test to send a test message.

How to check or retry deliveries

  1. Select Log on the webhook.
  2. For a failed delivery, select Retry. It goes out on the next delivery run.

How to rotate a webhook's signing secret

  1. Select More, then Rotate secret, and confirm.
  2. Copy the new secret and update the receiving system; it rejects deliveries until it has the new secret.

Tips

  • Treat Slack and Teams webhook addresses as secrets. After saving, the address is masked and cannot be viewed again; enter a new one only to replace it.
  • Webhook addresses must be reachable on the public internet over HTTPS on port 443 or 8443. Private network addresses are refused.
  • Failed deliveries are retried after 1 minute, 5 minutes, 30 minutes, 2 hours and 12 hours. After 20 failures in a row the webhook is switched off and its creator is emailed.
  • Each delivery carries an X-Lavawall-Signature header; the Using the API tab shows how to check it.
  • API responses use UTC times and page with a limit of 1 to 200 items per request.

Troubleshooting

  • "Only a GRC administrator can manage API tokens and webhooks for this company.": Ask a GRC administrator, or have your GRC role changed in Compliance Settings.
  • "This company already has 25 active tokens.": Revoke one you no longer use.
  • "This company already has 10 webhooks.": Delete one first.
  • "That is ten test messages in ten minutes.": Wait a few minutes before testing again.
  • "Test not delivered": The receiver did not accept the message. Check the address and that the receiving service is up.

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.