Webhook Widget

Protocol

Authentication

The widget sends the same token or password with every request. Use the format your server already supports. You can configure the last three options in the app.

SchemeHow to configureWhat is sent
Query token Write it into the URL: ?key=s3cret Your parameter, preserved exactly
Basic, no UI https://user:pass@host/feed Authorization: Basic …
Basic Hook → Authentication → Basic Authorization: Basic …
Bearer Hook → Authentication → Bearer token Authorization: Bearer …
Custom header Hook → Authentication → Custom header e.g. X-API-Key: …
Zero-configuration forms
https://you.example/widget?key=s3cret

# Or with credentials in the URL, which are moved into a header before the
# request leaves the device:
https://user:pass@you.example/widget

Credentials written into a URL are moved into a header before the request goes out. Userinfo in a URL is too widely mishandled to leave in place — it ends up in caches, logs and error messages. An explicitly configured scheme overrides anything embedded in the URL.

Verifying on your side
app.get("/widget", (request, response) => {
  const token = request.headers.authorization?.replace(/^Bearer /, "");
  if (token !== process.env.WIDGET_TOKEN) {
    return response.status(401).json({ error: "unauthorized" });
  }
  response.json({ view: buildView(request.query) });
});

Rules the client enforces

  • Credentials are never sent over plain HTTP, even with the HTTPS check disabled for local development. That opt-out exists for convenience; leaking a password does not.
  • A redirect to a different host drops the credential header. A server cannot bounce the widget somewhere else to harvest a token it was given. Same-host redirects keep it.
  • Passwords never reach a cache filename, an error message or the app's UI. Cache keys hash the credential-free URL, and anywhere a URL is displayed it is redacted to •••.
  • HTTPS is re-checked at every redirect hop, not just on the first request.

Where credentials are stored

A hook's URL and credential are stored together in the app, in the container the app and the widget share. The widget on the Home Screen holds only the hook's name, so a secret never reaches WidgetKit's configuration store.