createGitlabWebhook
Purpose and behavior
Section titled “Purpose and behavior”Create a GitLab trigger source. With signingToken it verifies the webhook-signature header of a whsec_ signing token (GitLab 19.0+) within a timestamp window and uses webhook-id; with token it compares X-Gitlab-Token and uses Idempotency-Key or X-Gitlab-Event-UUID. It reports object_kind, the object action and the user as gitlab:<username>.
Complete example and detailed rules.
Parameters and properties
Section titled “Parameters and properties”The fields below cover all variants; the signature specifies their allowed combinations.
optionsRequiredGitlabWebhookOptionsEither signingToken (recommended, signs the body) or token (legacy plain-text header); signingToken is used when both are set.options.signingTokenVariant-dependentTriggerSecretwhsec_ signing token of the GitLab webhook (GitLab 19.0+) verifying webhook-signature, or a callback returning every currently accepted token (old and new during a rotation). An empty string throws at creation; a callback that fails or returns nothing, or a token without the whsec_ prefix, denies requests.options.toleranceMsVariant-dependentnumber | undefinedAccepted clock difference for the request timestamp, in milliseconds; defaults to 300000 (5 minutes). A value that is not a positive integer throws at creation.options.tokenVariant-dependentTriggerSecretSecret token compared in constant time with X-Gitlab-Token, or a callback returning every currently accepted token; weaker because the body is not signed. An empty string throws at creation; a callback that fails or returns nothing denies requests.