Permissions
Updating settings requires an admin role on a dashboard session. Members and API-key auth are rejected with403.
Request body
string
URL Tumban will use when a scan is submitted without an explicit
callback_url. Both http and https are accepted (prefer https
in production). Setting it once removes the need to send
callback_url on every request.The host must resolve to a public address. The URL is rejected with
422 when the safety check fails — a disallowed scheme, a missing
host, a DNS-resolution failure, or a private/internal/reserved
address range (RFC1918, loopback, link-local, multicast, CGNAT) — to
defend against SSRF.Response
Returns the updated org settings document. See Get org settings for the field reference.Example
Errors
Using the dashboard
1
Open Webhooks
From the sidebar, click Webhooks.
2
Set the default callback URL
In the Default Callback URL tile, enter your webhook URL in
the URL field (placeholder
https://your-app.example/webhook)
and click Save.Tumban rejects URLs that target private or internal addresses.
The dashboard surfaces the error inline before submitting:
“This URL targets a private/internal address. Webhooks must use
a public URL.” The server’s check is authoritative.The Default Callback URL controls are visible to all members, but
the underlying endpoint is admin-only — a non-admin who clicks
Save gets a
403.
