GitHub Actions · AsyncAPI Specification
Github Actions Webhooks
Version
View Spec
View on GitHub
CI/CDContinuous IntegrationContinuous DeploymentDevOpsPipelinesWorkflowsAutomationDeveloper ToolsSoftware DevelopmentBuild AutomationT1GitHubAsyncAPIEvents
AsyncAPI Specification
generated: '2026-09-17'
method: searched
source: >-
https://docs.github.com/en/webhooks/webhook-events-and-payloads (event
catalog and delivery headers) and
https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com
(machine-readable JSON Schema per event + action, enumerated over the GitHub
contents API on 2026-09-17).
description: >-
The event surface for GitHub Actions. GitHub publishes no AsyncAPI document —
probed and absent — but it does publish a complete, versioned, machine-readable
webhook contract: one JSON Schema per event AND per action type, maintained in
the octokit/webhooks repository and shipped to npm as @octokit/webhooks-schemas.
This file catalogues the nine events an Actions consumer subscribes to, their
action types as the schemas enumerate them, the delivery headers, and the
signing scheme. Actions is unusual in being both a webhook PRODUCER (run and
job lifecycle) and a webhook CONSUMER (repository_dispatch and workflow_dispatch
start workflows), and the deployment_protection_rule event is a two-way
callback, not a notification.
asyncapi_spec:
published: false
probed: true
note: >-
No AsyncAPI document is published at any GitHub host, and none is referenced
from the webhooks documentation. The JSON Schema set below is the real
machine-readable event contract; nothing was generated to stand in for an
AsyncAPI that does not exist.
transport:
protocol: HTTPS
method: POST
content_types: [application/json, application/x-www-form-urlencoded]
configuration_scopes: [repository, organization, enterprise, GitHub App, GitHub Marketplace]
docs: https://docs.github.com/en/webhooks/about-webhooks
delivery_headers:
- {name: X-GitHub-Hook-ID, description: The unique identifier of the webhook.}
- {name: X-GitHub-Event, description: The name of the event that triggered the delivery.}
- {name: X-GitHub-Delivery, description: A globally unique GUID identifying the event.}
- {name: X-Hub-Signature, description: 'HMAC SHA-1 hex digest of the body, keyed with the webhook secret. Legacy; kept for compatibility.'}
- {name: X-Hub-Signature-256, description: 'HMAC SHA-256 hex digest of the body, keyed with the webhook secret. The recommended verification header.'}
- {name: User-Agent, description: Always prefixed GitHub-Hookshot/.}
- {name: X-GitHub-Hook-Installation-Target-Type, description: The type of resource the webhook was created on.}
- {name: X-GitHub-Hook-Installation-Target-ID, description: The identifier of the resource the webhook was created on.}
security:
signing: HMAC SHA-256 over the raw request body, shared secret
header: X-Hub-Signature-256
verification_docs: https://docs.github.com/en/webhooks/using-webhooks/validating-webhook-deliveries
note: The secret is optional at configuration time; unsigned deliveries carry no signature header at all.
redelivery:
supported: true
docs: https://docs.github.com/en/webhooks/testing-and-troubleshooting-webhooks/redelivering-webhooks
note: Failed deliveries can be redelivered by hand or automatically, and every delivery is inspectable for a retention window.
events:
- name: workflow_run
direction: outbound
action_types: [completed, in_progress, requested]
description: A workflow run was requested, started, or finished.
permission: 'GitHub Apps need at least read access to the "Actions" repository permission.'
schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/workflow_run
related_rest: [listWorkflowRuns, getWorkflowRun]
- name: workflow_job
direction: outbound
action_types: [completed, in_progress, queued, waiting]
description: >-
A job in a workflow run changed state. `queued` is the event self-hosted
runner autoscalers subscribe to; `waiting` means the job is blocked on a
deployment protection rule.
schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/workflow_job
related_rest: [listJobsForWorkflowRun, getJobForWorkflowRun]
- name: workflow_dispatch
direction: inbound
action_types: []
description: >-
A workflow was manually triggered. The inbound twin of the REST
createWorkflowDispatch operation — the same event an agent raises by
calling the API.
schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/workflow_dispatch
related_rest: [createWorkflowDispatch]
- name: check_run
direction: outbound
action_types: [completed, created, requested_action, rerequested]
description: >-
A check run was created, finished, re-requested, or a user clicked a
requested action. `rerequested` and `requested_action` are inbound
prompts to an app, not just notifications.
schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/check_run
- name: check_suite
direction: outbound
action_types: [completed, requested, rerequested]
description: A check suite was requested, re-requested, or completed.
schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/check_suite
- name: deployment
direction: outbound
action_types: [created]
description: A deployment was created, typically by a workflow job targeting an environment.
schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/deployment
- name: deployment_status
direction: outbound
action_types: [created]
description: A deployment status was created.
schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/deployment_status
- name: deployment_protection_rule
direction: bidirectional
action_types: [requested]
description: >-
A custom deployment protection rule was requested for an environment. The
payload carries deployment_callback_url, which the receiver POSTs back to
in order to approve or reject — this is a callback contract, not a
notification, and it is the event that lets an external system gate a
deployment.
schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/deployment_protection_rule
related_rest: [reviewCustomGatesForRun]
- name: deployment_review
direction: outbound
action_types: [approved, rejected, requested]
description: A deployment review was requested, approved, or rejected.
schemas: https://github.com/octokit/webhooks/tree/main/payload-schemas/api.github.com/deployment_review
related_rest: [getPendingDeployments, reviewPendingDeployments]
event_count: 9
action_type_count: 20
schema_registry:
repository: https://github.com/octokit/webhooks
path: payload-schemas/api.github.com
format: JSON Schema (draft-07)
package:
registry: npm
name: "@octokit/webhooks-schemas"
url: https://www.npmjs.com/package/@octokit/webhooks-schemas
version: 7.6.1
published: '2024-10-03'
note: >-
The published npm package is nearly two years behind the repository it is
generated from; consumers wanting current schemas read the repo directly.
typescript_types:
registry: npm
name: "@octokit/webhooks-types"
url: https://www.npmjs.com/package/@octokit/webhooks-types
docs:
events: https://docs.github.com/en/webhooks/webhook-events-and-payloads
about: https://docs.github.com/en/webhooks/about-webhooks
best_practices: https://docs.github.com/en/webhooks/using-webhooks/best-practices-for-using-webhooks
events_that_trigger_workflows: https://docs.github.com/en/actions/reference/events-that-trigger-workflows
Work with this as data
Every AsyncAPI spec here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for asyncapi
4 MCP tools reach this
find_asyncapisBrowse and filter every AsyncAPI spec in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This AsyncAPI spec
curl "https://apis.io/api/v1/asyncapis/github-actions-webhooks"
All asyncapi
curl "https://apis.io/api/v1/asyncapis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.