Help

API keys and webhooks

Most workspaces never need these. They let your own tools talk to ConfigCheckup: an API key lets another program read your data, and a webhook tells another program when something happens. Both are on the Growth and Scale plans.

Do you need them?

Probably not, if you use ConfigCheckup through its own screens, emails and the Teams or Slack alerts under Settings. Consider them when you want to:

  • show tenant scores and findings in your own dashboard or reporting tool;
  • start an assessment from a script or another system, for example after onboarding a client;
  • send an alert somewhere ConfigCheckup does not post to directly, such as a ticketing flow or an automation platform.

If none of those apply, you can ignore this part of Settings.

API keys

An API key is like a password for a program. Whatever holds the key can read your workspace’s tenants, assessments, findings and reports, so treat it with the same care as an admin password.

Create one

  1. In ConfigCheckup, go to Settings → API and webhooks. You need the Admin or Owner role.
  2. Name the key after what will use it, for example “Power BI” or “Onboarding script”, so you know what breaks if you revoke it.
  3. Choose what it can do. Read is always included; add Queue assessments only if the tool needs to start assessments.
  4. Choose when it expires. Shorter is safer; you can always create another.
  5. Copy the key straight away. It is shown once; only a fingerprint of it is stored, so it cannot be shown again.

Give the key to whoever is building the connection, along with the API reference, which lists every endpoint.

Webhooks

A webhook is the other direction: when something happens, ConfigCheckup sends a short message to a web address you choose. Nothing has to keep asking whether anything changed.

You choose which of these it sends:

EventWhen it is sent
Assessment completedAn assessment finished
Assessment failedAn assessment could not finish
Drift detectedA critical control stopped passing between assessments
Security eventA new admin, a risky app consent, an MFA method removed and similar
Report readyA report is ready to download

Add one

  1. Get a web address that can receive the message. Automation tools give you one: in Power Automate, the trigger “When an HTTP request is received”; in Zapier or Make, a webhook trigger. It must start with https://.
  2. In Settings → API and webhooks, add the address and tick the events you want.
  3. Press Send test to check it arrives. Pause it at any time without deleting it.

Each message is signed with a secret, so the receiving end can prove it came from ConfigCheckup. Automation tools usually do not need this; a developer building their own receiver should check it, as described in the API reference.

Keeping them safe

  • One key per tool, so revoking one does not break the others.
  • Revoke a key straight away if it may have been shared or leaked, and when the tool that used it is retired.
  • Keys stop working if your plan no longer includes the API, and start again if it does.
  • Creating and revoking keys, and adding and removing webhooks, are recorded in the audit log.