Integrations & webhooks
Connect Jira, GitHub or Slack before you launch a pentest, or subscribe to signed tenant webhooks — two channels, not the same product surface as Rank support tickets.
Two outbound channels
Rank can push finding and control events in two ways:
- Integrations — Rank opens, updates or closes a ticket in Jira, GitHub Issues or Slack. Jira and GitHub can also call back when that ticket moves.
- Tenant webhooks — Rank
POSTs a signed JSON envelope to an HTTPS URL you own. Your code interprets it. One subscription covers every pentest of its owner (you, or a team).
You can use both on the same events. Neither is the Tickets API, which is Rank’s internal support Jira — how you file issues with Rank, not how findings land in your tracker.
Providers today are jira, github and slack only. There is no GitLab, ServiceNow, Teams or Linear connector.
How many connections and webhook subscriptions you may hold depends on tier.
Create integrations before the pentest
File the connection before you create and launch pentests. Tickets fire from live events (vulnerability.created, vulnerability.validated, …). An integration connected after findings already exist does not backfill them — use a sync of that pentest if you need the current inventory pushed. Findings whose validation_status is failed never open tickets.
Typical setup: name the connection, store provider credentials (never returned on later reads), map events, optionally map Rank fields to tracker fields. Then test credentials. Sync is the backfill path.
Inbound close → retest
Jira and GitHub can post back when a linked ticket changes. Closing a ticket marks the finding resolved and, when remediation policy auto_retest_on_ticket_close is on (the default), queues a retest. Slack has no inbound.
Deleting an integration is refused while any linked ticket is closed_pending_retest, unless you discard those pending retests.
Webhooks vs integrations
A webhook delivers the envelope for your own handler. Verify it with HMAC (X-Rank-Timestamp + X-Rank-Signature: v1= of {timestamp}.{raw_body}) — the SDK helper is rank.verify_signature. An integration is Rank talking to the tracker so you do not host that handler.
Prefer tenant webhooks (/webhooks) over legacy per-pentest hooks. The event catalog — finding, pentest and control names — is on Webhooks.
Where to go next
Jira, GitHub and Slack: create, test, sync, links and inbound callbacks.
WebhooksTenant subscriptions, HMAC verification, deliveries and the event catalog.
Push findings to Jira, GitHub or SlackRunnable recipe: create the integration before the pentest.
Tenant webhooksSubscribe, verify signatures and list deliveries.
Tickets APIRank’s internal support Jira — a different product surface.