OpenAI safety alert notifications on your phone.

Get a High-priority push notification when OpenAI raises a safety alert for your project, or warns, deactivates or blocks one of your users.

safety.alert.createdAI & LLMsSecurity
How it works

Three steps to your first push

STEP 01

Install the recipe

One click in Studio gives you a personal webhook URL.

STEP 02

Paste your URL into OpenAI

Add it as a webhook for safety.alert.created, safety.warning_issued and safety.deactivation_issued.

STEP 03

Get a push on your phone

With the text, sound and buttons from the recipe.

Setup

How to set up the OpenAI safety.alert.created, safety.warning_issued and safety.deactivation_issued webhook

  1. Click Install in Studio and sign in. The recipe is added to your account and you get a personal webhook URL.
  2. In the OpenAI platform, open Settings > Project > Webhooks (platform.openai.com/settings/project/webhooks) and click Create.
  3. Give the endpoint a name and paste your webhook URL as the URL.https://••••••••/•••••••• your personal URL, shown after install
  4. Tick the safety.alert.created, safety.warning_issued and safety.deactivation_issued event types and save. Webhooks are per project, so repeat this for each project you want pushes from.
  5. Tick **safety.alert.created** (misalignment monitoring alerts for this project), and **safety.warning_issued** and **safety.deactivation_issued** if you pass a `safety_identifier` for your end users. Enterprise workspaces can also tick **safety.org_alert.created**. If your project offers **safety_identifier.blocked**, the recipe handles that too.
  6. The alert, warning and deactivation webhooks only carry an ID, not the details. The push tells you which API call returns them (`GET /v1/safety/alerts/{id}` or `GET /v1/safety/cases/{id}`).
  7. Receiving alerts doesn't replace handling `misalignment_policy_violation` errors in your app.
  8. OpenAI signs every delivery (Standard Webhooks: `webhook-id`, `webhook-timestamp`, `webhook-signature`), but JustPush doesn't check that signature yet, so keep your endpoint URL private.
The code

What runs when the webhook arrives

Studio calls handleRequest(request) with the incoming webhook and sends the message it returns. It's yours after install; change anything.

transform.js
1// OpenAI → safety.alert.created / safety.org_alert.created / safety.warning_issued /
2// safety.deactivation_issued / safety_identifier.blocked
3// Fires when OpenAI raises a safety alert for your project or workspace, warns or deactivates one of
4// your end users (by safety identifier), or blocks a request.
5// Docs: https://developers.openai.com/api/reference/resources/webhooks
6//
7// Alerts, warnings and deactivations only carry an ID to look up with the API
8// (GET /v1/safety/alerts/{id} or GET /v1/safety/cases/{id}).
9
10// Each event, how to word it, and how loud to be.
11const EVENTS = {
12 "safety.alert.created": {
13 title: "🛡️ OpenAI safety alert",
14 text: "A safety alert was raised for your API project",
15 lookup: "/v1/safety/alerts/",
16 priority: 1, // High: OpenAI wants you to review something your app did
17 },
18 "safety.org_alert.created": {
19 title: "🛡️ OpenAI workspace safety alert",
20 text: "A safety alert was raised for your enterprise workspace",
21 lookup: "/v1/safety/alerts/",
22 priority: 1, // High: same, across the workspace
23 },
24 "safety.deactivation_issued": {
25 title: "⛔ User deactivated by OpenAI",
26 text: "OpenAI deactivated one of your users' safety identifiers",
27 lookup: "/v1/safety/cases/",
28 priority: 1, // High: one of your users is cut off; you may need to act
29 },
30 "safety.warning_issued": {
31 title: "⚠️ OpenAI safety warning",
32 text: "OpenAI issued a warning for one of your users' safety identifiers",
33 lookup: "/v1/safety/cases/",
34 priority: 0, // Normal: a warning, nothing is blocked yet
35 },
36 "safety_identifier.blocked": {
37 title: "⚠️ Request blocked by OpenAI",
38 text: "A request was blocked",
39 lookup: null,
40 priority: 0, // Normal: a single request was stopped; can be frequent for a bad actor
41 },
42}
43
44// Table lookup that ignores inherited names such as "toString".
45function pick(table, key, fallback) {
46 return typeof key === "string" && Object.prototype.hasOwnProperty.call(table, key) ? table[key] : fallback
47}
48
49// Short, safe identifiers only; anything else is left out of the text.
50function clean(value) {
51 return typeof value === "string" && /^[A-Za-z0-9_.:@-]{1,128}$/.test(value) ? value : null
52}
53
54function handleRequest(request) {
55 const body = request.body && typeof request.body === "object" ? request.body : {}
56 const event = pick(EVENTS, body.type, null)
57
58 // Guard: only safety events, so other OpenAI events on this integration stay quiet.
59 if (!event) {
60 console.log(`Ignoring OpenAI "${typeof body.type === "string" ? body.type : "unknown"}" event`)
61 return null
62 }
63
64 const data = body.data && typeof body.data === "object" ? body.data : {}
65 let message
66
67 if (body.type === "safety_identifier.blocked") {
68 // Documented fields: safety_category (e.g. "bio", "cyber"), safety_identifier, model, project_id.
69 const category = clean(data.safety_category)
70 const user = clean(data.safety_identifier)
71 const model = clean(data.model)
72 message =
73 event.text +
74 (category ? ` (${category})` : "") +
75 (user ? ` for user ${user}` : "") +
76 (model ? ` on ${model}` : "") +
77 "."
78 } else {
79 const id = clean(data.id)
80 message = `${event.text}.` + (id ? ` Look it up with GET ${event.lookup}${id}` : "")
81 }
82
83 return {
84 title: event.title,
85 message,
86 topic: "OpenAI",
87 priority: event.priority,
88 }
89}
Payload

The OpenAI safety.alert.created webhook

This is what OpenAI sends to your URL for safety.alert.created, safety.warning_issued and safety.deactivation_issued. It is a sample, trimmed to the fields recipes use.

safety.alert.created · sample.json
1{
2 "id": "evt_123",
3 "data": {
4 "id": "alert_0123456789abcdef0123456789abcdef"
5 },
6 "type": "safety.alert.created",
7 "object": "event",
8 "created_at": 1790668800
9}
FAQ

OpenAI safety alert notifications: questions

Does this work on iPhone and Android?

Yes. Install the JustPush app from the App Store or Google Play and sign in. Every phone signed in to your account gets the notification.

Do I need to write code?

No. Install the recipe in Studio, paste your webhook URL into OpenAI and you are done. The code is there if you want to change the text, the sound or the buttons.

Can I change what the notification says?

Yes. After install the recipe's code is yours. Edit it in Studio and test it against the sample payload before you save.

What does it cost?

JustPush is free for 30 days. After that it's $19.99 a year, or $39.99 once. There is no extra charge for recipes.

Ready when you are

OpenAI on your phone in two minutes.

Install the recipe, paste one URL, done. Free for 30 days, no credit card required.