Cloudflare Webhooks Are Free: Website Alerts in Home Assistant
Bring Cloudflare certificate, tunnel, and origin alerts into Home Assistant with authenticated webhooks, persistent Repairs, and verified recovery.
I use Cloudflare for vCloudInfo, and I want problems with the blog to show up in the same place as problems with the house. Certificate warnings and tunnel failures are easy to miss when they live in a separate inbox. Sending those events into Home Assistant gives me a persistent alert where I already check system health.

Free webhook delivery opens up a useful connection
Cloudflare now supports webhook destinations on all plans, including Free. That lets an eligible alert send an HTTP request to a receiver as part of its delivery. The official webhook setup guide covers the destination URL, shared secret, and connection test. Individual alert types still have their own plan requirements; free delivery does not make every monitoring product free.
My setup connects Universal SSL certificate alerts, Tunnel Health, and Passive Origin Monitoring to Home Assistant. We removed the five-minute notification-history lookup and the email delivery path from this workflow. The receiver now waits for Cloudflare to send an event, and it does not need a Cloudflare API token to retrieve notification history.
If webhooks are new to you, my earlier guide to adding webhooks to Home Assistant introduces the basic idea: an outside service sends an event that your smart home can use. This Cloudflare example adds authentication and incident tracking around that connection.
What happens when an alert arrives
I use a custom Cloudflare alert receiver with a Home Assistant Cloud webhook. It checks the cf-webhook-auth header against a separate shared secret, then checks the account identity on alert payloads. A request must pass those checks before it can become a Home Assistant event.
The receiver tracks incidents by alert type and resource. Repeated deliveries update the existing incident, older events cannot overwrite newer state, and the records survive a restart. The infrastructure package turns those events into persistent Repairs and notifications. That gives me something I can inspect and resolve without searching through repeated messages.
Recovery matters just as much as delivery. Successful tunnel and certificate events can clear the corresponding incident. For mapped website origins, the receiver can reuse a fresh healthy report from an existing website probe after a five-minute minimum age. An alert does not disappear just because a timer ran out. This fits the approach I use for internet monitoring in Home Assistant: keep the signal and the evidence behind it visible.
Connecting your own website alerts
The receiver is custom code, so treat the repository as an example to adapt. Its README documents the secret values, account ID, and recovery-entity mapping. The surrounding infrastructure package contains other parts of my setup; copying that whole file would bring in unrelated dependencies.
- Configure the receiver with a random webhook identifier and a separate shared secret. Keep both private.
- Obtain the delivery URL through
cloudflare_alerts.create_cloudhook. My example uses Home Assistant Cloud, which has its own subscription. - In Cloudflare, create a webhook destination using that URL and secret, test the connection, and attach it to the alert policies available for your account.
- Check delivery counts with
cloudflare_alerts.get_status, then separately verify that a test incident reaches Repairs and can be cleared.
There are two different tests here. Cloudflare’s generic destination test increments the receiver’s test counter without creating a Repair. The video shows an authenticated synthetic certificate alert used to exercise the incident path, followed by cleanup of that test incident. It is a demonstration of delivery and presentation, not footage of an actual certificate outage.
Certificate problems stay available for human review. An incoming alert does not grant permission to change DNS, security settings, or account access. Start with visible notifications and verified recovery; add any automated response deliberately.
Watch the Home Assistant example
The short video shows the three policies, the receiver connection, and the test Repair in Home Assistant. If you run a website alongside your smart home, this is a useful way to bring the two together. Happy Automating!

