Skip to content

feat(serverless): Allow passing auth headers to webhooks - #602

Open
khushhhhh wants to merge 1 commit into
runpod:mainfrom
khushhhhh:feat/413-webhook-auth-headers
Open

khushhhhh wants to merge 1 commit into
runpod:mainfrom
khushhhhh:feat/413-webhook-auth-headers

Conversation

@khushhhhh

Copy link
Copy Markdown

Problem

Resolves #413.
Currently, the serverless worker hardcodes the headers for webhook transmissions (Content-Type and charset). When users need to secure their webhook endpoints (e.g., using a bearer token or API key to prevent unauthorized payloads), there is no built-in way to pass an Authorization header back to the configured endpoint.

Reproduction

  1. Configure a serverless endpoint with RUNPOD_WEBHOOK_POST_OUTPUT pointing to an authenticated URL (e.g., expecting a Bearer token).
  2. The payload fails to deliver with a 401/403 status because the worker strips or ignores any authentication credentials.

Fix

Updated _transmit inside runpod/serverless/modules/rp_http.py to dynamically check for RUNPOD_WEBHOOK_AUTHORIZATION or RUNPOD_WEBHOOK_HEADER_AUTH environment variables. If present, it injects the Authorization header into the outgoing POST request payload. This allows secure endpoints without breaking backward compatibility for unauthenticated endpoints.

Testing

  • Verified locally by setting RUNPOD_WEBHOOK_AUTHORIZATION="Bearer token" and intercepting the webhook output.
  • All existing tests pass.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow to pass auth headers to webhook call

1 participant