Developer Tools
GitLab (Signing Token) Webhooks
DevOps platform with Git repos, CI/CD, and project management. Receive events for pushes, merge requests, pipelines, and more. Uses GitLab's newer Signing Token auth (HMAC-SHA256, Standard Webhooks spec) — the mode GitLab now recommends for new webhooks.
Connecting GitLab (Signing Token) to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into GitLab (Signing Token). Then:
- 1Go to your GitLab project → Settings → Webhooks and click "Add new webhook"
- 2Paste your Hookbase ingest URL into the URL field (no query string)
- 3Under Signing token, click "Generate signing token" and copy it now — GitLab shows it only once
- 4Select the trigger events, then click "Add webhook" (or "Save changes") — the token only goes live when the form is saved
- 5Paste the token (whsec_...) into Hookbase's Signing token field; if you click "Regenerate token" later, paste the new one
Signature verification
Set the source's provider to gitlab-signing-token and paste the signing secret. Every request is checked before the event is stored, and anything that fails is rejected rather than quietly recorded.
- Algorithm
- HMAC-SHA256 (Standard Webhooks spec)
- Header
- webhook-signature
- Where to find the secret
- GitLab project (or group) → Settings → Webhooks → Signing token → "Generate signing token" (shown once; copy it, then click "Add webhook" / "Save changes" so it takes effect)
GitLab (Signing Token) event types
7 of the events people route most often. Hookbase accepts every event GitLab (Signing Token) sends, whether or not it is listed here.
Push Hook
Commits pushed to a branch
Merge Request Hook
Merge request created, updated, or merged
Pipeline Hook
CI/CD pipeline status changed
Issue Hook
Issue created, updated, or closed
Tag Push Hook
Tag created or deleted
Job Hook
CI/CD job status changed
Note Hook
Comment added to an issue, MR, or commit
What a GitLab (Signing Token) webhook looks like
A Push Hook payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"object_kind": "push",
"event_name": "push",
"ref": "refs/heads/main",
"user_name": "Example User",
"project": {
"id": 123,
"name": "my-project",
"web_url": "https://gitlab.com/user/my-project"
},
"commits": [
{
"id": "abc123",
"message": "Update README",
"author": {
"name": "Example User"
}
}
],
"total_commits_count": 1
}Start receiving GitLab (Signing Token) webhooks
Create a source, paste the URL into GitLab (Signing Token), and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free