Skip to main content
LangSmith Engine can notify you when it opens a new issue, links a new trace to an existing issue, or fails to complete a run. Deliver these notifications to a Slack channel, a Jira Automation incoming webhook, or an HTTP webhook endpoint. Each destination has its own event types and minimum priority, so you can route urgent issues to a paging webhook while sending every issue to a Slack channel.

Add a destination

Notification destinations are configured per tracing project or agent environment. On the Engine page, click Configure Engine, then under Notifications click Add. If no destination exists, the editor opens automatically. For each destination, choose: To be alerted when a watched issue recurs, click Alert me via Slack on the issue, which opens the same Notifications section.

Event types

For new destinations, the Notify when picker offers issue.created and issue.trace.added. Existing subscriptions can also receive issue.agent_run.failed. A destination created without an explicit list of event types receives only issue.created.

Severity filtering

The Minimum issue severity setting is stored as a severity_threshold from 0 to 3. For issue events, a notification is delivered only when the issue’s severity is less than or equal to the threshold. Lower numbers are more urgent. The picker offers High severity only (1), Medium and high severity (2), and All severities (3). For example, a destination with severity_threshold: 1 receives events for URGENT (0) and HIGH (1) issues only. Severity thresholds do not apply to issue.agent_run.failed, because run-failure events are scoped to an Engine session rather than to a specific issue.

Notify a Slack channel

If Slack is not configured on your self-hosted instance, the Slack tab shows Contact your operator to enable Slack notifications. The operator creates a Slack app and configures its credentials. You then connect a workspace through Slack authorization. To add a Slack destination:
1

Connect a Slack workspace

Connecting a Slack workspace is an organization-level action you perform once, not per project. Connecting or disconnecting a workspace requires the organization:manage permission. In your LangSmith instance, open Settings, go to your organization’s General settings, and under Slack click Connect Slack. Authorize the configured app in Slack. You can connect more than one Slack workspace to an organization.
2

Add a Slack destination

On the Engine page, click Configure Engine. Under Notifications, click Add if the editor is not already open. Select the Slack tab, then use the channel selector to choose a workspace and channel. If no workspace is connected, click Connect Slack in the channel selector and complete authorization.
3

Choose events and severity

Under Notify when, select which event types post a message to the channel. Under Minimum issue severity, choose which issue severities trigger a notification. Click Add to save.
LangSmith joins the selected public channel when it first delivers a message, if needed. To post to a private channel, invite the configured Slack app to that channel in Slack first, then refresh the channel picker. Each Slack message includes the issue title, description, and severity, a View issue link back to LangSmith, and (for issue events) a chart of the issue’s recurrence over time. If a workspace’s connection becomes invalid, for example, the app is removed from Slack, its destinations stop delivering until you reconnect it from your organization’s General settings. Slack destinations use the configured Slack app to post messages. They do not send the webhook payload, so webhook signing secrets and custom headers do not apply.

Create Jira work items

The Jira destination sends Engine events to a Jira Automation incoming webhook. Configure a Jira rule to turn new Engine issues into Jira work items. LangSmith sends the webhook payload with the X-Automation-Webhook-Token header. Jira destinations use this token for authentication and do not have an HMAC signing secret. Use the final incoming-webhook URL. Jira deliveries do not follow redirects, including redirects on the same host. A 3xx response is a permanent delivery error and is not retried. This keeps the token and payload on the configured endpoint. You need permission to manage Jira automation rules and a project where the rule can create work items. Jira Cloud hosts the incoming webhook on Atlassian’s infrastructure. For Jira Data Center, verify that your installed version’s endpoint accepts the required token header. LangSmith’s deployment type does not determine whether you use Jira Cloud or Data Center. To create a work item for each new Engine issue:
1

Configure the incoming webhook in Jira

Create a Jira Automation rule with an Incoming webhook trigger. If Jira requires a saved rule to generate the URL, save it without enabling it first.Select No work items from the webhook, called No issues from the webhook in older interfaces. Engine sends its own event payload, rather than Jira issue keys.Generate the trigger’s secret/token. Copy the webhook URL and token before saving. Keep the token out of the URL; LangSmith sends it in the authentication header.
2

Add the Jira creation action

Restrict the rule to the intended project. Add a Create work item action, called Create issue in older interfaces. Select an existing project and issue type, and configure any fields Jira requires.For Jira Cloud, set Summary to {{webhookData.object.name}}. Set Description to:
Jira Cloud exposes the envelope’s data member as webhookData. Use webhookData.object.* for issue fields. The extra .data in webhookData.data.object.name resolves to an empty summary. Verify payload handling in your installed Jira Data Center version before using these mappings there.
3

Add the Jira destination in LangSmith

On the Engine page, click Configure Engine. Under Notifications, click Add and select Jira. Enter the Jira Webhook URL and Jira webhook token from the trigger.Under Notify when, select only issue.created for this creation rule. Choose the Minimum issue severity, then click Add. Enable the rule in Jira.
4

Verify Jira created the work item

After Engine creates an issue that matches your severity filter, check Jira’s automation audit log. Confirm that the rule succeeds and creates a work item with the expected summary, description, severity, and LangSmith issue link.An HTTP success means Jira accepted the webhook, not that it created a work item. Rule conditions, required fields, actor permissions, and automation usage limits can prevent creation.
LangSmith stores the Jira token without displaying it again. To replace it, enter a new token. Changing the webhook URL also requires entering a token for the replacement URL. If you lose the token, rotate it in Jira and update the LangSmith destination.

Reach a private Jira endpoint

Private Jira endpoints require network access from your LangSmith deployment. In self-hosted and hybrid deployments, webhook delivery runs in the customer data plane. Configure the following before adding the destination:
  • Network access: Allow DNS resolution and outbound connectivity to Jira from both the LangSmith API and webhook delivery processes. Allow their source addresses through Jira’s firewall.
  • Private addresses: If the endpoint resolves to a private IP, set SSRF_ALLOW_PRIVATE_IPS_WEBHOOKS=true for both processes. Kubernetes-internal hostnames also require SSRF_ALLOW_K8S_INTERNAL=true. Other webhook URL protections remain active. For configuration, see Set self-hosted environment variables.
  • TLS trust: If Jira uses a private certificate authority, add its CA to the webhook delivery processes’ trusted roots. Use system roots or SSL_CERT_FILE, retain other required roots, and keep TLS verification enabled.

Send to a webhook

Forward Engine events to your own incident-management, paging, or chat tooling. Add a destination and select the Webhook tab. Enter a URL and, optionally, custom headers. Each delivery is signed so you can verify its authenticity.

Delivery

LangSmith sends a POST request with a JSON body to your webhook URL. The request uses Content-Type: application/json and includes any custom headers you attached to the destination.
Retries deliver a byte-identical payload, including the same id. Dedupe on id so a retried delivery does not produce a duplicate downstream effect.

Custom headers

You can attach arbitrary headers to each destination (for example, Authorization: Bearer …) to authenticate the caller at your endpoint. Content-Type is always set by LangSmith and cannot be overridden.

Signing secret

Each Webhook destination has a signing secret. LangSmith uses this secret to sign the raw webhook request body and sends the result in the X-LangSmith-Signature header. Jira destinations use their token header instead. The header value has this format:
Verify the signature before parsing or acting on the payload. The HMAC input is the exact raw request body bytes, and the HMAC key is the destination’s signing secret. Do not parse and reserialize the JSON body before verification.

Roll a signing secret

Roll a signing secret when it may have been exposed, or when your organization’s credential rotation policy requires a new secret. To roll a secret, open the destination row in the Engine settings panel, click Roll signing secret, and confirm. LangSmith generates a new signing secret and uses it for future webhook deliveries immediately. The previous secret stops signing deliveries as soon as the roll completes. After rolling the secret, update every consumer that verifies X-LangSmith-Signature with the new value.

Test your endpoint

Before pointing a real destination at your endpoint, send a sample payload to verify it accepts and acknowledges within the 20-second timeout:
Use the example body from issue.created as sample-issue-created.json. Verify that:
  • The custom Authorization header arrives and matches the secret you configured on the destination.
  • The handler persists the event keyed by its id so retries are deduped.
  • The handler returns 2xx before kicking off slow downstream work.

Security

  • Webhook URLs are validated when the destination is created and again at delivery time. Private and metadata IP ranges are blocked in SaaS. Both http:// and https:// are accepted; use https:// so the payload and any custom headers are not sent in cleartext.
  • LangSmith signs webhook bodies with the destination’s signing secret. Verify X-LangSmith-Signature before processing the payload.
  • You can also set custom headers on the destination, such as Authorization: Bearer …, for routing or additional authentication at your endpoint.
  • Dedupe on the event id so that a retried delivery does not cause a duplicate notification.

Best practices

  • Acknowledge fast. Respond with 2xx as soon as you have persisted the event. Move slow work (fan-out, paging, downstream API calls) onto a queue so your handler stays within the 20-second timeout.
  • Tolerate unknown event types. Ignore type values your handler does not recognize. New event types may be added without notice.
  • Tolerate new fields. Parse payloads with a permissive schema. New fields may be added to existing event types without notice.

Webhook payload reference

Webhook and Jira destinations receive the JSON payloads below. Slack destinations do not.

Event envelope

Every event delivered to your endpoint uses the same outer JSON shape.

Issue data.object

For issue.created and issue.trace.added, data.object is a snapshot of the issue. Treat it as the authoritative state of the issue at the time the event was generated.

Run failure data.object

For issue.agent_run.failed, data.object describes the Engine run that failed.

data.trace

data.trace is included only on issue.trace.added events.

Batch coalescing

A single upstream action can produce multiple webhook events. When Engine opens a new issue and attaches five traces to it, you receive one issue.created event and five issue.trace.added events, all sharing the same request_id. Use request_id to group these into a single downstream notification.

issue.created

Sent when LangSmith Engine creates a new issue. data.trace is omitted.

issue.trace.added

Sent when a new trace is linked to an existing issue. data.trace describes the linked trace.

issue.agent_run.failed

Sent when LangSmith Engine fails to complete a run. This event is session-scoped, so it does not include data.trace and does not use severity filtering.