Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Approval Notifications & Webhooks

When an AI agent requests a capability that evaluates to APPROVAL_REQUIRED, Dmint can automatically post real-time alerts to Slack, Discord, and Microsoft Teams.
Human operators are notified immediately with full context and the exact command needed to approve the action—without requiring active polling or keeping a browser tab open.
┌─────────────────┐ │ AI Agent │ Attempts sensitive tool call └────────┬────────┘ │ ▼ ┌─────────────────┐ │ Dmint Gate │ Evaluates policy: APPROVAL_REQUIRED └────────┬────────┘ │ ├─────────────────────────────────────────┐ ▼ ▼ ┌─────────────────┐ ┌─────────────────┐ │ Approval Store │ (Atomic Record Created)│ Webhook Engine │ (Fire-and-forget) └─────────────────┘ └────────┬────────┘ │ ┌───────────────────────────────┼───────────────────────────────┐ ▼ ▼ ▼ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │ Slack │ │ Discord │ │ MS Teams │ │ (Channel) │ │ (Channel) │ │ (Channel) │ └─────────────┘ └─────────────┘ └─────────────┘

Configuration via Environment Variables

Webhooks are configured simply through environment variables. Any combination of channels is supported:
Environment VariablePlatformDescription
DMINT_SLACK_WEBHOOK_URLSlackIncoming webhook URL for a Slack channel
DMINT_DISCORD_WEBHOOK_URLDiscordWebhook URL for a Discord channel
DMINT_TEAMS_WEBHOOK_URLMicrosoft TeamsIncoming webhook or Power Automate workflow URL
DMINT_WEBHOOK_TIMEOUTAllHTTP request timeout in seconds (default: 3.0)
Zero-Config Default: If no webhook environment variables are set, notification dispatch is a complete no-op. Webhook configuration is never mandatory.

How to Get Webhook URLs

1. Slack

  1. In your Slack workspace, navigate to Slack API: Your Apps.
  2. Create a new app or select an existing one, then select Incoming Webhooks.
  3. Toggle Activate Incoming Webhooks to On.
  4. Click Add New Webhook to Workspace, choose your target channel, and authorize it.
  5. Copy the generated Webhook URL and set:
    export DMINT_SLACK_WEBHOOK_URL="https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX"

2. Discord

  1. Open Discord and go to your server's target text channel.
  2. Click the gear icon (Edit Channel) $\to$ Integrations $\to$ Webhooks.
  3. Click New Webhook, give it a name (e.g. Dmint Guard), and select the channel.
  4. Click Copy Webhook URL and set:
    export DMINT_DISCORD_WEBHOOK_URL="https://discord.com/api/webhooks/123456789012345678/abcdefghijklmnopqrstuvwxyz"

3. Microsoft Teams

  1. In Microsoft Teams, navigate to the channel where you want notifications.
  2. Click ... (More options) next to the channel name $\to$ Workflows (or Connectors).
  3. Select Post to a channel when a webhook request is received.
  4. Follow the setup wizard and copy the generated webhook URL:
    export DMINT_TEAMS_WEBHOOK_URL="https://prod-XX.location.logic.azure.com/workflows/..."
    (Note: DMINT_MSTEAMS_WEBHOOK_URL is also accepted as an alias).

Notification Content

Every webhook notification includes the critical context needed for a human operator to audit and act on the request:
  • Approval ID: The unique non-sequential identifier (apr_...).
  • Tool & Action: The target capability requested by the agent (e.g. bash.execute, github.merge_pr).
  • Resource / Target: The specific asset or parameter target (e.g. /var/log, repo:prod-main).
  • Agent / Principal: The authenticated identity of the requesting AI agent.
  • Copy-Paste Action Command: The exact CLI command ready to execute:
    dmint approve <approval_id>

Real-Time Policy Denial Alerts

In addition to APPROVAL_REQUIRED events, Dmint can also dispatch real-time security alerts whenever a tool execution is explicitly blocked (DENY). This gives security teams instant visibility into policy violations, prompt injection attempts, or unauthorized tool calls directly in your team's Slack, Discord, or Microsoft Teams channels.
Denial notifications include:
  • Status: DENIED
  • Tool & Action: Requested capability (e.g. bash.execute, filesystem.write)
  • Resource / Target: Target resource or path
  • Agent Identity: The requesting agent principal ID
  • Timestamp: Exact UTC timestamp of the denial event
Programmatically, you can dispatch denial alerts via dispatch_denial_webhook(request) or WebhookNotifier.send_policy_denied(request). In MCP gateways, explicit policy denials are forwarded automatically when webhook URLs are configured.

Security & Isolation Invariant

Strict Notification Boundary: Webhook delivery is strictly an asynchronous notification side-effect. Under no circumstances will a webhook error (such as a network timeout, 4xx/5xx HTTP error, DNS resolution failure, or unreachable endpoint) ever block, weaken, or alter the authorization decision path.
  • Fail-Closed Guarantee: If a tool requires approval, the agent is paused and ApprovalRequiredError is raised regardless of whether webhooks succeed or fail.
  • Non-Blocking Dispatch: Outgoing webhooks execute with a short timeout (3.0s by default), preventing sluggish external APIs from stalling tool evaluation.
  • Tamper Resistance: The notification displays the canonical RFC 8785 request binding, ensuring that the command dmint approve <id> only authorizes the exact immutable request.