Knowledge base

Deploy hook (scan after each deploy)

The deploy hook starts a light scan right after you deploy: it re-checks the scripts that changed for secrets, the headers, the certificate and the riskiest files, so a leaked key is caught within minutes instead of at the next nightly check.

  1. On the project's Settings tab create the deploy hook. The URL contains a secret and is shown once; creating a new one replaces the old one.
  2. Call it from your deploy pipeline after a successful deploy:
curl -X POST "https://vigavo.com/api/v1/hooks/deploy/<project-id>/<secret>"

In Vercel, Netlify or GitHub Actions add this as a post-deploy step. The answer is 202 when the check was queued and 404 for a wrong URL. Up to 6 calls per hour per project are accepted. The check is a light scan, not a full scan, so your score does not change until the next full scan.

Last reviewed Oct 7, 2026, 12:00:00 AM

Still stuck? Send a ticket

Feedback
Type