Source type

Linear Source

Linear sources receive issue, comment, project, cycle, and workspace events with Linear signature verification and provider header capture.

Direct answer

Linear signs the raw request body with HMAC-SHA256 and sends the hexadecimal digest in Linear-Signature. Linear-Delivery and Linear-Event identify the delivery and event family.

LINEARPOST, PUT, PATCH, DELETEWebhook Signing SecretProductivity
Linear sends webhook traffic to a FastHook source, FastHook validates the provider contract, records the request, and routes accepted events through connections to destinations.LinearProviderPOST, PUT, PATCH, DELETESignedFastHookSource URLLINEARProvider credentialsignatureVerify before queue401 on auth failure405 on wrong methodAcceptedRequestverified: trueConnections route the accepted request to destinationsFilters, transformations, retries, replay, and destination signatures stay downstream from source verification.
FastHook keeps the provider-facing contract on the source. Accepted requests are stored before routing, while rejected requests keep enough evidence to debug signature, method, and challenge failures.

When to use this source type

Choose the LINEAR source type when Linear is the system sending webhook requests into FastHook. The source type keeps sender-specific setup close to the source: accepted methods, verification headers, challenge handling, and the exact credential fields are documented together so operators do not need to translate a generic HMAC form into a provider-specific contract.

FastHook verifies the source before accepted traffic is queued. A valid request is stored with verified: true, then connections route it to destinations. A bad signature, wrong token, or missing provider header is rejected as SOURCE_AUTH_FAILED. A method outside the allowed set is rejected as SOURCE_METHOD_NOT_ALLOWED.

FastHook configuration

In the dashboard, create a source, set Source Type to Linear, keep Authenticate enabled when verification is required, and fill the fields below.

Source Type

LINEAR

Allowed methods

POST, PUT, PATCH, DELETE

Authentication

Provider signature

Webhook Signing Secret

Copy this value from Linear and store it on the FastHook source.

Linear source config
{
  "type": "LINEAR",
  "config": {
    "auth_type": "PROVIDER_SIGNATURE",
    "auth": {
      "provider": "LINEAR",
      "webhook_signing_secret": "provider-secret"
    },
    "allowed_http_methods": ["POST","PUT","PATCH","DELETE"]
  }
}
Create Linear source with cURL
curl -X POST "https://api.fasthook.io/v1/sources" \
  -H "Authorization: Bearer $FASTHOOK_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "name": "Linear production",
  "type": "LINEAR",
  "config": {
    "auth_type": "PROVIDER_SIGNATURE",
    "auth": {
      "provider": "LINEAR",
      "webhook_signing_secret": "provider-secret"
    },
    "allowed_http_methods": [
      "POST",
      "PUT",
      "PATCH",
      "DELETE"
    ]
  }
}'

HTTP methods

This source accepts only the methods listed below. Keep the set narrow so provider mistakes and accidental test calls are visible as rejected requests instead of being silently accepted.

POSTPUTPATCHDELETE

Headers and verification

FastHook verifies the provider-specific values below before the request is accepted. The comparison is done against the raw inbound request body or the exact provider-specific signing input described here.

linear-signature

HMAC-SHA256 hex signature over the raw body.

linear-delivery

Unique Linear delivery id, useful for debugging and idempotency.

linear-event

Linear event family such as Issue, Comment, Project, or Cycle.

FastHook computes HMAC-SHA256 hex over the raw body and compares it to linear-signature while preserving Linear provider headers for downstream routing.

Provider setup checklist

  1. Create a Linear webhook and use the FastHook Source URL.
  2. Paste the Linear webhook secret into FastHook.
  3. Use payload type, action fields, Linear-Event, and Linear-Delivery for connection routing and debugging.
  4. Open Linear webhooks documentation when you need the provider's event list, dashboard steps, or retry policy.

Supported event types and payload shape

FastHook stores the original Linear request before routing so filters, transformations, retries, and replay decisions can use the same provider evidence. Use stable headers and payload fields for routing rather than relying on receiver-side logs alone.

  • Linear webhook events should be routed by stable provider headers, event type fields, object ids, or payload paths that do not change between retries.
  • Use provider delivery ids or business object ids as idempotency inputs before retrying or replaying traffic.

Troubleshooting

  • No request appears: the provider is not calling the generated FastHook Source URL, the source URL was copied before saving, or the provider has not completed its setup validation.
  • 405 method rejected: the provider sent a method outside POST, PUT, PATCH, DELETE. Edit the source only if the provider documentation says that method is expected.
  • 401 source auth failed: check the configured FastHook field, the provider signing secret, and the header names listed on this page.
  • Signature mismatch: make sure the provider signs the same public Source URL it calls and that no proxy, parser, or manual resend changed the raw request body before FastHook received it.

Linear source FAQ

What should I inspect first when Linear delivery fails?

Start with FastHook Requests to confirm the provider reached the source and passed verification. Then open the routed Event and destination Attempts when ingress succeeded but downstream delivery failed.

Can I retry or replay Linear webhook traffic?

Yes, after the receiver or route is fixed. Confirm idempotency with provider delivery ids or business object ids before replaying traffic that can create external side effects.

Related docs