Vaultic
Web App

Webhooks & audit log

Workspace-level outbound webhooks, and the write-event audit trail.

Webhooks

Workspace-level outbound webhooks — generic HMAC-signed JSON, or a Slack incoming webhook. The table shows kind, URL, subscribed events, active/disabled status, an expandable recent-deliveries list (timestamp, event, ok/failed with error or status code), and a delete action.

Creating one takes a URL, a kind, and a checkbox list of event types to subscribe to. New generic (non-Slack) webhooks show a one-time signing-secret banner right after creation.

The Webhooks page, with the one-time signing secret banner and the webhooks table

See CLI: sharing & webhooks for the full event catalog and the CLI equivalent.

Activity

The workspace-wide audit log: When / Actor / Action / Target key / Project / Source (web, API, or token) for every write event. Only write events are logged here — masked list/get reads are not.

Supports date-range filters (From/To) and an Export button that downloads the filtered log as CSV or JSON.

The Activity audit log, listing write events with actor, action, target, and source

Every reveal and every export is its own distinct audit event (secret.revealed, environment.exported) — separate from secret.created/updated/list — so revealing or exporting a value is always individually traceable.

On this page