08
Integrations
Settings → Integrations shows everything ChangeBox is wired to — telemetry coming in, Slack, Cursor, GitHub, API tokens — and the outbound connections that carry each change's timeline into the systems your organisation already runs on. Every outbound call is logged with its response and retried on a backoff.
Connected now is the inventory: what is receiving and what is sending, with a line of live status on each tile. Receiving telemetry is configured per app on its Signals page (the ingest key and the OTLP endpoint live there); the tile links you to it. Connections are the outbound ones you add here:
Webhook
Every event (or a chosen set) POSTed to your URL, signed. Build anything on it.
ServiceNow
A change_request per change at the Ship gate. CAB approves there; ChangeBox releases. Implemented and closed mirrored both ways.
Jira Service Management
A change request with approvers. The final decision approves or sends back the Ship gate.
Jira · Linear
An issue per change with comments as it moves. Tracking only; approvals stay in ChangeBox.
Datadog export · OpenTelemetry export
Outbound copies of the error batches your services already send to ChangeBox telemetry — Datadog Logs, or any OTLP/HTTP logs endpoint. Send once, land in both. Change events are not sent here.
Webhooks
Add a webhook with a URL; ChangeBox generates a signing secret and shows it once. Each delivery is one POST with the envelope below. Verify the signature before trusting the body: it is HMAC-SHA256 over `${t}.${rawBody}` with your secret, and t must be within five minutes.
POST https://hooks.example.com/changebox
X-ChangeBox-Event: change.ship_approved
X-ChangeBox-Delivery: dlv_9f3…
X-ChangeBox-Signature: t=1758900000,v1=3f1a…
{ "id": "cev_…", "type": "change.ship_approved", "at": "2026-09-26T21:00:00.000Z",
"org": { "id": "org_…" }, "app": { "id": "app_…", "name": "Cinema Studio" },
"change": { "id": "chg_…", "publicId": "CB-12", "status": "pr_ready", "phase": "ready_to_ship",
"impact": "broken", "description": "…", "expected": "…", "url": "…", "environment": "Production",
"prUrl": "https://github.com/…/pull/142", "prNumber": 142, "assignee": "Sam",
"reporter": { "name": "Dana", "email": "dana@…" },
"consoleUrl": "https://changebox.ai/changes/chg_…", "evidenceUrl": "…/evidence" },
"event": { "actorType": "operator", "actorName": "Priya", "via": "slack", "message": "Priya approved the ship",
"metadata": { "message": "Looks good." } } }Answer 2xx quickly and do the work afterwards. A 5xx, 408 or 429 is retried after 1 minute, then 5, 30, 120 and 720; after that the delivery is dead and the connection shows the error. Any other 4xx is not retried. Retry a delivery by hand from the log. Node example:
import { createHmac, timingSafeEqual } from "node:crypto";
export function verify(secret, header, rawBody) {
const { t, v1 } = Object.fromEntries(header.split(",").map((p) => p.split("=")));
if (Math.abs(Date.now() / 1000 - Number(t)) > 300) return false;
const expected = createHmac("sha256", secret).update(`${t}.${rawBody}`).digest("hex");
return expected.length === v1.length && timingSafeEqual(Buffer.from(expected), Buffer.from(v1));
}ServiceNow
Connect with your instance and a credential for a user with itil and the sn_chg_rest scope (user:password or an OAuth bearer token). Pick a change model: Normal goes to Assess so CAB sees it, Standard uses your pre-approved template, Emergency for the rare case. When a change reaches the Ship gate — the pull request is ready and reviewed — ChangeBox creates the change_request with the description, justification, implementation and backout plans, the evidence link as the test plan, and correlation_id set to the ChangeBox change id.
Approvals come back through the connection's inbound URL. A Flow Designer action or business rule on sysapproval_approver (or on change_request state) POSTs to it with the inbound secret as a bearer token:
POST https://changebox.ai/api/integrations/servicenow/webhook/int_…
Authorization: Bearer whsec_…
{ "number": "CHG0030001", "approval": "approved", "approver": "Morgan Lee", "comments": "CAB 2026-09-26" }
approval approved → Ship gate approved via servicenow; merge + release follow
approval rejected → Ship gate rejected; the note is the agent's follow-up
state 3 (Closed) → change confirmed
state 4 (Canceled) → noted on the timelineGoing the other way, ChangeBox writes work notes as the change moves and sets the record's state: Implement when the PR merges, Review when it is live, Closed successful when the reporter confirms. Set the app's ship policy to approver so nothing goes live before the record is approved.
Jira Service Management
Connect with your site, the account email and an API token, the service desk id and a request type that has an approval step. At the Ship gate ChangeBox creates the request; then it polls the approval every five minutes (for up to fourteen days) and, when finalDecision is approved or declined, decides the Ship gate with the approver's name. For no delay, add a Jira Automation rule on approval that sends a web request to the inbound URL:
POST https://changebox.ai/api/integrations/jsm/webhook/int_…
Authorization: Bearer whsec_…
{ "issueKey": "{{issue.key}}", "decision": "approved", "approver": "{{initiator.displayName}}" }ChangeBox comments on the request as the change goes live, is confirmed, or is sent back.
Jira and Linear
For teams who track work there. An issue is created when a change is reported — project key and issue type for Jira, team id or key for Linear — and comments follow the change: picked up, PR opened, review clean, ship approved or sent back, live, confirmed, reopened, blocked, closed. Each issue links back to the change and its evidence. These are tracking links; approvals happen in ChangeBox or the change system.
Scope, health, audit
A connection applies to every app in the workspace or to one. Pause it to hold deliveries (they resume, nothing is lost); remove it to drop its log and links. The connection shows its last error and counts of delivered, retrying, dead and queued. Connecting, pausing, removing, rotating an inbound secret and every decision applied from an external system are on the audit log, and the evidence packet lists the external records with the control Approved in the change system.