Monitor workflow · Developer

Signed webhook application

Receive a durable signal when a new disruption Event is coded near a Red Sea operating area, then hydrate application state with complete API results.

The webhook contains at most ten representative matches; the run replay request retrieves the complete result with QU. Verify the signature over timestamp plus raw bytes before parsing, enforce the five-minute replay window, and deduplicate event IDs. localhost HTTP is allowed only behind the local development flag; production destinations must be public HTTPS. Use custom QU-backed polling only when the deliberately constrained Monitor builder cannot express the recurring logic. volume_spike is deferred; the trigger is new_matches. A Monitor reads one lane: this one reads Events, because an application dedupes and reconciles discrete incidents. Point a second Monitor at Stories if the app also needs coverage.

POST /api/v2/monitors  # specification 1 of 1
{
  "name": "Red Sea operating-area disruption",
  "description": "Signed webhook intake for new shipping disruption Events near the southern Red Sea.",
  "subject": {
    "type": "place",
    "latitude": 15,
    "longitude": 42,
    "radius_km": 250
  },
  "criteria": {
    "data": "events",
    "search": "port closure, vessel attack, shipping disruption",
    "countries": [],
    "family_filters": {
      "cameoplus": {
        "domains": [
          "ECONOMIC",
          "INFRASTRUCTURE"
        ],
        "subcategories": []
      },
      "conflict": {
        "categories": [
          "Explosions/Remote violence",
          "Strategic developments"
        ],
        "subcategories": []
      }
    },
    "fatalities_only": false
  },
  "trigger": {
    "type": "new_matches"
  },
  "schedule": {
    "cadence": "hourly",
    "timezone": "UTC",
    "daily_hour": 8
  },
  "delivery": {
    "email": false,
    "webhook_url": "http://127.0.0.1:8787/webhooks/gdelt"
  }
}

Expected notification result

Email summarizes the same run. Signed webhooks use this typed Constitution fixture; total, included, and truncation are explicit.

[
  {
    "name": "test",
    "payload": {
      "schema_version": "1",
      "id": "evt_demo_test_001",
      "type": "monitor.test",
      "created_at": "2026-08-24T12:00:00.000Z",
      "monitor": {
        "id": "mon_demo_test",
        "name": "Webhook setup test"
      },
      "run": null,
      "trigger": null,
      "data": {
        "matches": []
      },
      "test": {
        "status": "ok",
        "message": "GDELT Cloud Monitor webhook test"
      },
      "links": {
        "monitor": "https://gdeltcloud.com/monitors/mon_demo_test",
        "run": null,
        "matches": null
      }
    }
  },
  {
    "name": "event",
    "payload": {
      "schema_version": "1",
      "id": "evt_demo_event_001",
      "type": "monitor.triggered",
      "created_at": "2026-08-24T12:00:00.000Z",
      "monitor": {
        "id": "mon_demo_supply",
        "name": "Supplier disruption watch"
      },
      "run": {
        "id": "run_demo_event_001",
        "scheduled_for": "2026-08-24T12:00:00.000Z",
        "window_start": "2026-08-24T11:00:00.000Z",
        "window_end": "2026-08-24T12:00:00.000Z",
        "cadence": "hourly"
      },
      "trigger": {
        "type": "new_matches",
        "total_matches": 1,
        "included_matches": 1,
        "truncated": false,
        "next_cursor": "eyJvIjowfQ"
      },
      "data": {
        "matches": [
          {
            "kind": "event",
            "family": "cameoplus",
            "item": {
              "id": "cameoplus:demo-event-001",
              "url": "https://example.com/events/demo-event-001",
              "primary_story_url": "https://example.com/news/demo-event-001",
              "family": "cameoplus",
              "title": "Port authority temporarily restricts cargo traffic",
              "title_source": "coder_title",
              "summary": "A temporary operating restriction affected cargo movements at the port.",
              "event_date": "2026-08-24",
              "observed_at": "2026-08-24T10:30:00.000Z",
              "event_date_basis": "explicit_date",
              "event_date_evidence": "The notice states the restriction began on August 24.",
              "coded_at": "2026-08-24T11:00:00.000Z",
              "updated_at": "2026-08-24T11:05:00.000Z",
              "processed_at": "2026-08-24T11:05:00.000Z",
              "category": "Economic activity",
              "subcategory": "EC04",
              "subcategory_label": "Trade Policy Action",
              "event_description": "Trade Policy Action",
              "taxonomy_status": "coded",
              "domain": "ECONOMY",
              "event_code": "EC04",
              "geo": {
                "country": "United States",
                "region": "Northern America",
                "continent": "North America",
                "admin1": "California",
                "location": "Los Angeles",
                "latitude": 34.0522,
                "longitude": -118.2437,
                "geo_precision": 1,
                "geo_precision_label": "city"
              },
              "geo_context": {
                "location_country": "United States",
                "actor_origin_countries": [
                  "United States"
                ]
              },
              "actors": [
                {
                  "name": "Port authority",
                  "country": "United States",
                  "role": "source",
                  "primary": true
                },
                {
                  "name": "Cargo operators",
                  "country": null,
                  "role": "target",
                  "primary": true
                }
              ],
              "metrics": {
                "significance": 0.62,
                "severity_tier": "moderate",
                "goldstein_scale": null,
                "magnitude": 0.54,
                "systemic_importance": 0.44,
                "propagation_potential": 0.58,
                "market_sensitivity": 0.61,
                "confidence": 0.91,
                "article_count": 4,
                "evidence_source_count": 3,
                "supporting_story_count": 1,
                "metric_version": "v1"
              },
              "has_fatalities": null,
              "fatalities": null,
              "fatalities_basis": null,
              "fatalities_corroboration": null,
              "fatalities_evidence": null,
              "fatalities_supporting_source_count": null,
              "injured": null,
              "civilians_killed": null,
              "civilians_injured": null,
              "civilian_targeting": null,
              "civilian_targeting_label": null,
              "story_refs": [
                {
                  "id": "story-demo-001",
                  "url": "https://example.com/stories/story-demo-001",
                  "title": "Port traffic restricted",
                  "story_date": "2026-08-24",
                  "article_count": 4
                }
              ],
              "entity_refs": [
                {
                  "id": "e_demo_port",
                  "name": "Port authority"
                }
              ],
              "top_articles": [
                {
                  "url": "https://example.com/news/demo-event-001",
                  "title": "Port traffic restricted",
                  "domain": "example.com",
                  "domain_avatar_url": null,
                  "rank": 1
                }
              ],
              "language_breakdown": [
                {
                  "language": "English",
                  "count": 4
                }
              ],
              "top_language": "English",
              "search_score": null,
              "incident": {
                "uid": "cameoplus:demo-event-001",
                "resolution": "unadjudicated",
                "confidence": null
              }
            }
          }
        ]
      },
      "links": {
        "monitor": "https://gdeltcloud.com/monitors/mon_demo_supply",
        "run": "https://gdeltcloud.com/monitors/mon_demo_supply/runs/run_demo_event_001",
        "matches": "https://gdeltcloud.com/api/v2/monitors/mon_demo_supply/runs/run_demo_event_001/matches"
      }
    }
  },
  {
    "name": "truncated",
    "payload": {
      "schema_version": "1",
      "id": "evt_demo_truncated_001",
      "type": "monitor.triggered",
      "created_at": "2026-08-24T12:00:00.000Z",
      "monitor": {
        "id": "mon_demo_high_volume",
        "name": "High-volume country watch"
      },
      "run": {
        "id": "run_demo_truncated_001",
        "scheduled_for": "2026-08-24T12:00:00.000Z",
        "window_start": "2026-08-24T11:00:00.000Z",
        "window_end": "2026-08-24T12:00:00.000Z",
        "cadence": "hourly"
      },
      "trigger": {
        "type": "new_matches",
        "total_matches": 37,
        "included_matches": 1,
        "truncated": true,
        "next_cursor": "eyJvIjowfQ"
      },
      "data": {
        "matches": [
          {
            "kind": "story",
            "item": {
              "id": "story-demo-truncated",
              "url": null,
              "title": "Representative result from a larger run",
              "story_date": "2026-08-24",
              "updated_at": null,
              "processed_at": null,
              "category": null,
              "category_code": null,
              "subcategory": null,
              "geo": {
                "country": "Brazil",
                "region": "South America",
                "continent": "South America",
                "admin1": null,
                "location": null,
                "latitude": null,
                "longitude": null,
                "geo_precision": null,
                "geo_precision_label": null
              },
              "geo_provenance": null,
              "geo_context": {
                "location_country": "Brazil",
                "actor_origin_countries": []
              },
              "metrics": {
                "significance": 0.42,
                "article_count": 2,
                "linked_event_count": 0,
                "max_linked_event_significance": 0,
                "civilian_targeting_event_count": 0
              },
              "has_events": false,
              "has_fatalities": null,
              "has_civilian_targeting": false,
              "fatalities": null,
              "linked_events": [],
              "entity_refs": [],
              "matched_categories": [],
              "top_articles": [],
              "language_breakdown": [],
              "top_language": null,
              "search_score": null
            }
          }
        ]
      },
      "links": {
        "monitor": "https://gdeltcloud.com/monitors/mon_demo_high_volume",
        "run": "https://gdeltcloud.com/monitors/mon_demo_high_volume/runs/run_demo_truncated_001",
        "matches": "https://gdeltcloud.com/api/v2/monitors/mon_demo_high_volume/runs/run_demo_truncated_001/matches"
      }
    }
  }
]

The stored Monitor specification

All three views use this same public API object.

{
  "name": "Red Sea operating-area disruption",
  "description": "Signed webhook intake for new shipping disruption Events near the southern Red Sea.",
  "subject": {
    "type": "place",
    "latitude": 15,
    "longitude": 42,
    "radius_km": 250
  },
  "criteria": {
    "data": "events",
    "search": "port closure, vessel attack, shipping disruption",
    "countries": [],
    "family_filters": {
      "cameoplus": {
        "domains": [
          "ECONOMIC",
          "INFRASTRUCTURE"
        ],
        "subcategories": []
      },
      "conflict": {
        "categories": [
          "Explosions/Remote violence",
          "Strategic developments"
        ],
        "subcategories": []
      }
    },
    "fatalities_only": false
  },
  "trigger": {
    "type": "new_matches"
  },
  "schedule": {
    "cadence": "hourly",
    "timezone": "UTC",
    "daily_hour": 8
  },
  "delivery": {
    "email": false,
    "webhook_url": "http://127.0.0.1:8787/webhooks/gdelt"
  }
}

After the notification

Scheduled checks cost 0 QU. Investigation and application calls use QU.

Persist X-GDELT-Event-Id with the application side effect so retries are idempotent.

Execute the run replay_requests for the complete Event result window.

Use custom recurring QU polling only for unsupported multi-endpoint logic, custom state, or custom schedules.