POST request with Content-Type: application/json or text/plain; charset=utf-8. Use secret custom headers for authentication.
Reserved HTTP transport headers and Content-Type cannot be overridden. The sender also supplies:
Validate authentication at the receiver before accepting work. Respond promptly with
2xx. A redirect fails rather than forwarding your credentials. If processing takes longer, accept the event and queue it in your own service.
Event schema
id, app, event, time, and message fields are present in JSON. Other fields are omitted when empty. error_category may describe a failed Scout job. detail is present only when nonempty and explicitly enabled for the destination. The sender never automatically serializes the full app settings or hook environment.
Design receivers to tolerate additional fields and new event names. JSON encoding preserves quotes and newlines in values. An HTTP delivery ID identifies an emission; it doesn’t guarantee that related Scout and Station events share an ID.
Manage destinations through the API
Both apps expose the same endpoints. Sign in as an admin, or use a manage automation token belonging to an admin. Use HTTPS and keep secret request files private.
For example, a creation request on Scout is:
id. Omit url and headers to preserve secrets; supply replacements to change them, or an empty headers object to clear headers. An empty or insecure URL is rejected. The flags url_configured and headers_configured in responses describe saved state, not retrievable secret values.
Tests use saved credentials and therefore don’t need a body. Errors report a safe message or HTTP status, never the receiver’s response body. See delivery limits and secret storage before relying on events for critical automation.