GitHub Actions · AsyncAPI Specification

Github Actions Webhooks

Version

View Spec View on GitHub CI/CDContinuous IntegrationContinuous DeploymentDevOpsPipelinesWorkflowsAutomationDeveloper ToolsSoftware DevelopmentBuild AutomationT1GitHubAsyncAPIEvents

AsyncAPI Specification

Raw ↑
generated: '2026-09-17'
method: searched
source: >-
  https://docs.github.com/en/webhooks/webhook-events-and-payloads (event
  catalog and delivery headers) and
  https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com
  (machine-readable JSON Schema per event + action, enumerated over the GitHub
  contents API on 2026-09-17).
description: >-
  The event surface for GitHub Actions. GitHub publishes no AsyncAPI document —
  probed and absent — but it does publish a complete, versioned, machine-readable
  webhook contract: one JSON Schema per event AND per action type, maintained in
  the octokit/webhooks repository and shipped to npm as @octokit/webhooks-schemas.
  This file catalogues the nine events an Actions consumer subscribes to, their
  action types as the schemas enumerate them, the delivery headers, and the
  signing scheme. Actions is unusual in being both a webhook PRODUCER (run and
  job lifecycle) and a webhook CONSUMER (repository_dispatch and workflow_dispatch
  start workflows), and the deployment_protection_rule event is a two-way
  callback, not a notification.
asyncapi_spec:
  published: false
  probed: true
  note: >-
    No AsyncAPI document is published at any GitHub host, and none is referenced
    from the webhooks documentation. The JSON Schema set below is the real
    machine-readable event contract; nothing was generated to stand in for an
    AsyncAPI that does not exist.
transport:
  protocol: HTTPS
  method: POST
  content_types: [application/json, application/x-www-form-urlencoded]
  configuration_scopes: [repository, organization, enterprise, GitHub App, GitHub Marketplace]
  docs: https://docs.github.com/en/webhooks/about-webhooks
delivery_headers:
  - {name: X-GitHub-Hook-ID, description: The unique identifier of the webhook.}
  - {name: X-GitHub-Event, description: The name of the event that triggered the delivery.}
  - {name: X-GitHub-Delivery, description: A globally unique GUID identifying the event.}
  - {name: X-Hub-Signature, description: 'HMAC SHA-1 hex digest of the body, keyed with the webhook secret. Legacy; kept for compatibility.'}
  - {name: X-Hub-Signature-256, description: 'HMAC SHA-256 hex digest of the body, keyed with the webhook secret. The recommended verification header.'}
  - {name: User-Agent, description: Always prefixed GitHub-Hookshot/.}
  - {name: X-GitHub-Hook-Installation-Target-Type, description: The type of resource the webhook was created on.}
  - {name: X-GitHub-Hook-Installation-Target-ID, description: The identifier of the resource the webhook was created on.}
security:
  signing: HMAC SHA-256 over the raw request body, shared secret
  header: X-Hub-Signature-256
  verification_docs: https://docs.github.com/en/webhooks/using-webhooks/validating-webhook-deliveries
  note: The secret is optional at configuration time; unsigned deliveries carry no signature header at all.
redelivery:
  supported: true
  docs: https://docs.github.com/en/webhooks/testing-and-troubleshooting-webhooks/redelivering-webhooks
  note: Failed deliveries can be redelivered by hand or automatically, and every delivery is inspectable for a retention window.
events:
  - name: workflow_run
    direction: outbound
    action_types: [completed, in_progress, requested]
    description: A workflow run was requested, started, or finished.
    permission: 'GitHub Apps need at least read access to the "Actions" repository permission.'
    schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/workflow_run
    related_rest: [listWorkflowRuns, getWorkflowRun]
  - name: workflow_job
    direction: outbound
    action_types: [completed, in_progress, queued, waiting]
    description: >-
      A job in a workflow run changed state. `queued` is the event self-hosted
      runner autoscalers subscribe to; `waiting` means the job is blocked on a
      deployment protection rule.
    schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/workflow_job
    related_rest: [listJobsForWorkflowRun, getJobForWorkflowRun]
  - name: workflow_dispatch
    direction: inbound
    action_types: []
    description: >-
      A workflow was manually triggered. The inbound twin of the REST
      createWorkflowDispatch operation — the same event an agent raises by
      calling the API.
    schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/workflow_dispatch
    related_rest: [createWorkflowDispatch]
  - name: check_run
    direction: outbound
    action_types: [completed, created, requested_action, rerequested]
    description: >-
      A check run was created, finished, re-requested, or a user clicked a
      requested action. `rerequested` and `requested_action` are inbound
      prompts to an app, not just notifications.
    schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/check_run
  - name: check_suite
    direction: outbound
    action_types: [completed, requested, rerequested]
    description: A check suite was requested, re-requested, or completed.
    schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/check_suite
  - name: deployment
    direction: outbound
    action_types: [created]
    description: A deployment was created, typically by a workflow job targeting an environment.
    schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/deployment
  - name: deployment_status
    direction: outbound
    action_types: [created]
    description: A deployment status was created.
    schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/deployment_status
  - name: deployment_protection_rule
    direction: bidirectional
    action_types: [requested]
    description: >-
      A custom deployment protection rule was requested for an environment. The
      payload carries deployment_callback_url, which the receiver POSTs back to
      in order to approve or reject — this is a callback contract, not a
      notification, and it is the event that lets an external system gate a
      deployment.
    schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/deployment_protection_rule
    related_rest: [reviewCustomGatesForRun]
  - name: deployment_review
    direction: outbound
    action_types: [approved, rejected, requested]
    description: A deployment review was requested, approved, or rejected.
    schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/deployment_review
    related_rest: [getPendingDeployments, reviewPendingDeployments]
event_count: 9
action_type_count: 20
schema_registry:
  repository: https://github.com/octokit/webhooks
  path: payload-schemas/api.github.com
  format: JSON Schema (draft-07)
  package:
    registry: npm
    name: "@octokit/webhooks-schemas"
    url: https://www.npmjs.com/package/@octokit/webhooks-schemas
    version: 7.6.1
    published: '2024-10-03'
    note: >-
      The published npm package is nearly two years behind the repository it is
      generated from; consumers wanting current schemas read the repo directly.
  typescript_types:
    registry: npm
    name: "@octokit/webhooks-types"
    url: https://www.npmjs.com/package/@octokit/webhooks-types
docs:
  events: https://docs.github.com/en/webhooks/webhook-events-and-payloads
  about: https://docs.github.com/en/webhooks/about-webhooks
  best_practices: https://docs.github.com/en/webhooks/using-webhooks/best-practices-for-using-webhooks
  events_that_trigger_workflows: https://docs.github.com/en/actions/reference/events-that-trigger-workflows

Work with this as data

Every AsyncAPI spec here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for asyncapi

4 MCP tools reach this
  • find_asyncapisBrowse and filter every AsyncAPI spec in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This AsyncAPI spec
curl "https://apis.io/api/v1/asyncapis/github-actions-webhooks"
All asyncapi
curl "https://apis.io/api/v1/asyncapis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.