# Webhook payload URL doesn't accept internal IP based value

**URL:** https://meta.discourse.org/t/webhook-payload-url-doesnt-accept-internal-ip-based-value/247762
**Category:** Feature
**Created:** [December 5, 2022, 9:33am UTC](https://meta.discourse.org/t/webhook-payload-url-doesnt-accept-internal-ip-based-value/247762 "2022-12-05T09:33:30Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![priteshvaviya](https://avatars.discourse-cdn.com/v4/letter/p/94ad74/32.png) [@priteshvaviya](https://meta.discourse.org/u/priteshvaviya)
#### Post date: [December 5, 2022, 9:33am UTC](https://meta.discourse.org/t/webhook-payload-url-doesnt-accept-internal-ip-based-value/247762/1 "2022-12-05T09:33:30Z")

</div>

Hi,

I have recently upgraded my discouse instance to Discourse/2.9.0.beta14 latest version from Discourse/2.9.0.beta3.  
The discourse webhook event has stopped working now.

This is the configuration  
payload URL: [http://server-name](http://server-name):port/rest : This is the internal rest api service that we have defined.

When I try to save this value, it gives the following error:  
“An error occurred: Payload URL cannot be used because it resolves to a blocked or internal IP”

The same value for payload URL: [http://server-name](http://server-name):port/rest used to work fine in the  
Discourse/2.9.0.beta3 discourse version.  
Is there something that has been updated in the latest version of discourse, or is this a bug?

Please could you let me know. Thanking in advance.

---

<div class="post-metadata">

### Author: ![MSG160](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/msg160/32/208781_2.png) [@MSG160](https://meta.discourse.org/u/MSG160)
#### Post date: [December 6, 2022, 9:13am UTC](https://meta.discourse.org/t/webhook-payload-url-doesnt-accept-internal-ip-based-value/247762/2 "2022-12-06T09:13:11Z")

</div>

This doesn’t sound right. The payload URL for webhooks may indeed be an internal resource if Discourse is self hosted. Not sure why you would want to stop being able to configure URLS or addresses that resolve internally for processing web hooks. There has been a change it seems to prevent invalid/bad website URLs on user profiles. Has that change crept into the validation for the webhook payload URL ?

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [December 6, 2022, 9:35am UTC](https://meta.discourse.org/t/webhook-payload-url-doesnt-accept-internal-ip-based-value/247762/3 "2022-12-06T09:35:52Z")

</div>

> [@MSG160](#):
>
> Not sure why you would want to stop being able to configure URLS or addresses that resolve internally for processing web hooks

Because it can also be a security issue where a Discourse admin could use webhooks to discover or attack internal resources on a network which is not theirs?

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [December 7, 2022, 12:11am UTC](https://meta.discourse.org/t/webhook-payload-url-doesnt-accept-internal-ip-based-value/247762/4 "2022-12-07T00:11:41Z")

</div>

Yeah, moved this to #Contribute > Feature, this can be used to fish information about an internal network. There are some knobs to tune the behavior on a specific instance.

---

<div class="post-metadata">

### Author: ![dpb](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@dpb](https://meta.discourse.org/u/dpb)
#### Post date: [February 10, 2023, 11:52am UTC](https://meta.discourse.org/t/webhook-payload-url-doesnt-accept-internal-ip-based-value/247762/5 "2023-02-10T11:52:07Z")

</div>

Our self-hosted instance is affected by this, as well. We would like to host the service that receives the webhook only on the internal docker network; there’s no need for it to be reachable from outside.

Is there a way to allow internal webhooks?

If I understand the issue correctly, internal webhooks are not allowed such that a discourse admin, who is not entitled as a server admin, may not spy on network internals. This is not an issue on our self-hosted instance, though; our discourse admins would know about our internal structure anyway.

I would suggest a setting in the `app.yml` config to allow internal webooks, or to provide a whitelist of internal domains/IPs. This way, the server admin (not the discourse admin) remains in control of who may use webhooks for the internal network.

---

<div class="post-metadata">

### Author: ![dpb](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@dpb](https://meta.discourse.org/u/dpb)
#### Post date: [February 10, 2023, 2:06pm UTC](https://meta.discourse.org/t/webhook-payload-url-doesnt-accept-internal-ip-based-value/247762/6 "2023-02-10T14:06:44Z")

</div>

I found a setting that allows to unblock specific internal hosts and is respected by the SSRF Protection mechanism that is causing the WebHooks to be blocked in the first place:

Use the setting `allowed_internal_hosts` to specify which internal hostnames are allowed in your webhook.

---

<div class="post-metadata">

### Author: ![Svetlozar\_Draganov](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/svetlozar_draganov/32/553310_2.png) [@Svetlozar\_Draganov](https://meta.discourse.org/u/Svetlozar_Draganov)
#### Post date: [August 21, 2026, 8:33am UTC](https://meta.discourse.org/t/webhook-payload-url-doesnt-accept-internal-ip-based-value/247762/7 "2026-08-21T08:33:25Z")

</div>

Can’t find this parameter in Admin panel, was it removed or renamed?  
Perhaps it’s available only or self-hosted version?

---

<div class="post-metadata">

### Author: ![Moin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/moin/32/554653_2.png) [@Moin](https://meta.discourse.org/u/Moin)
#### Post date: [August 21, 2026, 8:39am UTC](https://meta.discourse.org/t/webhook-payload-url-doesnt-accept-internal-ip-based-value/247762/8 "2026-08-21T08:39:15Z")

</div>

No, the `allowed_internal_hosts` site setting is still there.

 ![Screenshot_20260821_103652_Firefox](https://global.discourse-cdn.com/meta/original/4X/2/2/2/222b37b5b784edd40d0711c6c16b267f16dd4433.jpeg)

But I have the impression it is hidden for customers of Discourse hosting. But it’s not listed in [Hidden Settings on Discourse Hosted Sites](https://meta.discourse.org/t/hidden-settings-on-discourse-hosted-sites/310574). Still, if you are hosted by them and cannot find it, I’d contact their support.

---

<div class="post-metadata">

### Author: ![Svetlozar\_Draganov](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/svetlozar_draganov/32/553310_2.png) [@Svetlozar\_Draganov](https://meta.discourse.org/u/Svetlozar_Draganov)
#### Post date: [August 21, 2026, 8:52am UTC](https://meta.discourse.org/t/webhook-payload-url-doesnt-accept-internal-ip-based-value/247762/9 "2026-08-21T08:52:21Z")

</div>

I guess it’s available only for self-hosted version!  
This actually makes sense, cloud-version won’t be able to access private URL.
