Skip to content

JSM Operations (Opsgenie) ​

JSM Operations (formerly Opsgenie) Outgoing Webhook integrations POST alert lifecycle events to Exhale. Each tenant gets a unique HTTPS URL token. Exhale scrubs the payload, upserts a Pulse (source=opsgenie), and runs triage on Create.

See Sources for how JSM Operations fits with the other incoming webhooks.

Alert notes: After triage, Exhale can post a scrubbed summary to the JSM Operations (Opsgenie) alert. OAuth connect uses the JSM Ops REST API. The manual webhook path uses a stored GenieKey (US or EU API host) when notes are enabled on the JSM Operations card.

On the hosted app, use the URL Connections copies. It starts with https://exhaleoncall.com/webhooks/. The customer host does not publish /v1/webhooks/....


Endpoint ​

After Connect in Connections → Sources → On-call & paging → JSM Operations:

Preferred (keeps tokens out of proxy access logs):

POST https://exhaleoncall.com/webhooks/opsgenie

Send header X-Exhale-Webhook-Token: {token}.

Path form (also supported):

POST https://exhaleoncall.com/webhooks/opsgenie/{token}
  • token — opaque URL segment; this token authenticates the delivery (Opsgenie has no platform HMAC like PagerDuty). Treat the full webhook URL as a secret: Exhale stores only a hash for lookup, and teammates with the Viewer role cannot read it back from the Connections page.
  • Response: 202 Accepted with pulse_id, status, created, and message.

Unknown tokens return 404. Disabled or expired-trial tenants return 403.


Customer setup ​

Manual webhook ​

  1. Sign in as admin → Connections → Sources → JSM Operations.
  2. Click Connect JSM Operations and copy the webhook URL.
  3. In JSM Operations or leftover standalone Opsgenie, create an Outgoing Webhook integration and paste the Exhale URL.
  4. Enable create, acknowledge, and close (or equivalent) alert actions.
  5. Send test alert creates a synthetic pulse and marks the integration configured. Members and admins can send it.
  6. Optional: store a GenieKey and enable alert notes (United States or Europe API host).

See Jira Service Management's official guide: Integrate with Webhook. See Opsgenie's official guide: Integrate Opsgenie with Webhook.

Rotate webhook token replaces the previous URL right away. Update the vendor webhook after rotating. Connect, rotate, and GenieKey save return 400 while OAuth is connected.

OAuth (one-click) ​

Growth or higher. Manual and OAuth share one incoming slot and one JSM Operations row. Prefer this card when Exhale should register the Outgoing Webhook. Use the manual card for leftover standalone Opsgenie or when you want to paste the URL yourself.
  1. Sign in as admin → Connections → Sources → JSM Operations (OAuth).
  2. Click Connect with Atlassian and approve the Exhale app.
  3. Exhale exchanges the code, resolves your Atlassian cloud site, and creates a JSM Operations Webhook integration. That integration posts to Exhale’s /webhooks/opsgenie URL with header X-Exhale-Webhook-Token.
  4. Alert notes turn on and use the JSM Ops REST API. You do not store a GenieKey on this card. On-call schedule ids for JSM Operations also require this OAuth connection.

Disconnect OAuth deletes the remote Webhook integration, clears tokens, turns notes off, and returns the row to manual mode. A generic source disconnect returns 409.

Default scopes: read:ops-config:jira-service-management, write:ops-config:jira-service-management, delete:ops-config:jira-service-management, read:ops-alert:jira-service-management, write:ops-alert:jira-service-management, and offline_access.

If the platform OAuth app is not configured, start returns 503. If Atlassian has no JSM Operations site (standalone Opsgenie), connect returns 422 and you should use the manual card. A denied consent returns you to Connections with an error flash.


Payload shape ​

FieldRequiredNotes
alert.alertIdYesStable id for dedupe (source=opsgenie)
alert.messageNoPulse title
actionNoCreate, Acknowledge, Close; other actions do not change pulse status

Lifecycle mapping ​

Opsgenie actionPulse status
CreateReceived → triage
AcknowledgeAcknowledged
CloseResolved
Other (for example AddNote)Existing pulse payload only; 202 with no pulse when the alert is unknown

Example ​

bash
TOKEN="your-url-token"
curl -i -X POST "https://exhaleoncall.com/webhooks/opsgenie/${TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{"action":"Create","alert":{"alertId":"og-1","message":"CPU high"}}'

Auth API ​

Canonical paths are under /v1. The app calls them under /api. Writes need a session and CSRF. Connect, rotate, GenieKey save, and OAuth disconnect are admin. Send test alert is member or higher.

MethodPathNotes
GET/v1/auth/sources/opsgenieStatus, webhook path, connect mode, GenieKey flag, region, notes flag, OAuth token and cloud id when connected
PUT/v1/auth/sources/opsgenieGenieKey, notes toggle, US/EU region. 400 when OAuth is connected or notes are enabled without a key. Never returns the key
POST/v1/auth/sources/opsgenie/connectIssue a webhook token. 400 while OAuth is connected
POST/v1/auth/sources/opsgenie/rotate-tokenReplace the token. 400 while OAuth is connected
POST/v1/auth/sources/opsgenie/test-alertMember or higher. Synthetic Create ingest
GET/v1/auth/sources/opsgenie/oauth/startAdmin. Returns the Atlassian authorize URL. 503 when OAuth is not configured on the platform
DELETE/v1/auth/sources/opsgenie/oauthAdmin + CSRF. Disconnect OAuth

Secrets are never returned.


Exhale by Kolstrom Systems LLC