An incoming webhook is a secret address that posts into one channel. Anything that can send a webhook can use it: GitHub, GitLab, Jira automation, Zapier, Make, n8n, Jenkins, Grafana, Uptime Kuma or a few lines of your own script. Messages appear in the channel under the webhook's name.
Step 1: create the webhook
- As an owner or admin, open Apps and workflows from the admin menu.
- Under Incoming webhooks, give it a name (for example GitHub: website) and choose the channel it posts to.
- Choose what it sends: Slack-compatible for most tools, or GitHub for GitHub's own events.
- Create it. The address (and, for GitHub, a signing secret) is shown once. Copy them now.
Treat the address like a password: anyone who has it can post into that channel. If it leaks, remove the webhook and create a new one.
Connecting GitHub
- In your repository on GitHub, open Settings → Webhooks → Add webhook.
- Paste the address into Payload URL and set Content type to
application/json. - Paste the signing secret into Secret. Tandem checks every delivery against it and rejects anything unsigned.
- Choose the events you want. Tandem posts readable summaries of pushes, pull requests, issues, comments and releases.
Tools that speak Slack's format
Many tools have a "Slack webhook" option. Choose Slack-compatible when creating the webhook and paste the Tandem address wherever the tool asks for a Slack webhook URL. Tandem reads the message text, attachments and blocks.
Your own scripts
Send a JSON body with a text field:
curl -X POST -H 'Content-Type: application/json' -d '{"text":"Backup finished"}' https://your-company.thetandem.app/hooks/…
Messages can use the same formatting as chat: **bold**, _italic_, `code` and links.
Tips
- Give noisy sources their own channel (such as
#deploys) so people can mute it without missing conversations. - Start a thread on an alert to discuss it, and turn it into a task if it needs follow-up.
- To act from Tandem rather than post into it, add a custom slash command on the same page, or use the REST API with a personal access token.