Skip to main content
Update fields on the organization’s settings document. Only fields you include in the body are changed.

Permissions

Updating settings requires an admin role on a dashboard session. Members and API-key auth are rejected with 403.

Request body

string
URL Tumban will use when a scan is submitted without an explicit callback_url. Both http and https are accepted (prefer https in production). Setting it once removes the need to send callback_url on every request.The host must resolve to a public address. The URL is rejected with 422 when the safety check fails — a disallowed scheme, a missing host, a DNS-resolution failure, or a private/internal/reserved address range (RFC1918, loopback, link-local, multicast, CGNAT) — to defend against SSRF.

Response

Returns the updated org settings document. See Get org settings for the field reference.

Example

Errors

Using the dashboard

1

Open Webhooks

From the sidebar, click Webhooks.
2

Set the default callback URL

In the Default Callback URL tile, enter your webhook URL in the URL field (placeholder https://your-app.example/webhook) and click Save.Tumban rejects URLs that target private or internal addresses. The dashboard surfaces the error inline before submitting: “This URL targets a private/internal address. Webhooks must use a public URL.” The server’s check is authoritative.
The Default Callback URL controls are visible to all members, but the underlying endpoint is admin-only — a non-admin who clicks Save gets a 403.