---
title: "Receive penetration test webhook events"
method: POST
path: "/v1/security-penetration-tests/webhook"
tags: ["Security Penetration Tests"]
---

# Receive penetration test webhook events

`POST /v1/security-penetration-tests/webhook`

Receives signed JSON events from Maced. Signature is verified against MACED_WEBHOOK_SIGNING_SECRET using the SDK's verifyMacedWebhook helper.

## Headers

- `X-Organization-Id` string
- `X-Maced-Signature` string, required

## Response `200`

Webhook handled

## Other responses

- `400` — Invalid webhook payload
- `403` — Invalid webhook signature

## Changes

- **2026-04-30** `e3da57681861` — 1 breaking, 3 warning, 1 info
  - added the new required `header` request parameter `X-Maced-Signature`
  - deleted the `header` request parameter `X-Webhook-Id`
  - deleted the `header` request parameter `X-Webhook-Token`
  - deleted the `query` request parameter `webhookToken`
  - …1 more
- **2026-03-05** `946edaa856a9` — 1 warning
  - deleted the `query` request parameter `orgId`
- **2026-03-02** `9f44f6e28c23` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/om-network/apis/betayum-api/changes/v1/security-penetration-tests/webhook/post.md)

---

[API](https://skmtc.dev/om-network/apis/betayum-api.md) · [All operations](https://skmtc.dev/om-network/apis/betayum-api/llms.txt) · [OpenAPI document](https://skmtc.dev/om-network/apis/betayum-api/revisions/9dbc609fc132?raw)
