# OpenAI safety alert notifications on your phone > Get a High-priority push notification when OpenAI raises a safety alert for your project, or warns, deactivates or blocks one of your users. - Company: OpenAI (https://www.justpush.io/recipes/openai) - Event: `safety.alert.created` (safety.alert.created, safety.warning_issued and safety.deactivation_issued) - Tags: AI & LLMs, Security - Install: https://studio.justpush.io/recipes/openai/safety-alert - Web page: https://www.justpush.io/recipes/openai/safety-alert ## Setup 1. Click Install in Studio and sign in. The recipe is added to your account and you get a personal webhook URL. 2. In the OpenAI platform, open Settings > Project > Webhooks (platform.openai.com/settings/project/webhooks) and click Create. 3. Give the endpoint a name and paste your webhook URL (shown in Studio after install) as the URL. 4. Tick the safety.alert.created, safety.warning_issued and safety.deactivation_issued event types and save. Webhooks are per project, so repeat this for each project you want pushes from. 5. Tick **safety.alert.created** (misalignment monitoring alerts for this project), and **safety.warning_issued** and **safety.deactivation_issued** if you pass a `safety_identifier` for your end users. Enterprise workspaces can also tick **safety.org_alert.created**. If your project offers **safety_identifier.blocked**, the recipe handles that too. 6. The alert, warning and deactivation webhooks only carry an ID, not the details. The push tells you which API call returns them (`GET /v1/safety/alerts/{id}` or `GET /v1/safety/cases/{id}`). 7. Receiving alerts doesn't replace handling `misalignment_policy_violation` errors in your app. 8. OpenAI signs every delivery (Standard Webhooks: `webhook-id`, `webhook-timestamp`, `webhook-signature`), but JustPush doesn't check that signature yet, so keep your endpoint URL private. ## Code Studio calls `handleRequest(request)` with the incoming webhook (`{ method, headers, body, query, raw }`) and sends the message object it returns. Returning `null` sends nothing. ```js // OpenAI → safety.alert.created / safety.org_alert.created / safety.warning_issued / // safety.deactivation_issued / safety_identifier.blocked // Fires when OpenAI raises a safety alert for your project or workspace, warns or deactivates one of // your end users (by safety identifier), or blocks a request. // Docs: https://developers.openai.com/api/reference/resources/webhooks // // Alerts, warnings and deactivations only carry an ID to look up with the API // (GET /v1/safety/alerts/{id} or GET /v1/safety/cases/{id}). // Each event, how to word it, and how loud to be. const EVENTS = { "safety.alert.created": { title: "🛡️ OpenAI safety alert", text: "A safety alert was raised for your API project", lookup: "/v1/safety/alerts/", priority: 1, // High: OpenAI wants you to review something your app did }, "safety.org_alert.created": { title: "🛡️ OpenAI workspace safety alert", text: "A safety alert was raised for your enterprise workspace", lookup: "/v1/safety/alerts/", priority: 1, // High: same, across the workspace }, "safety.deactivation_issued": { title: "⛔ User deactivated by OpenAI", text: "OpenAI deactivated one of your users' safety identifiers", lookup: "/v1/safety/cases/", priority: 1, // High: one of your users is cut off; you may need to act }, "safety.warning_issued": { title: "⚠️ OpenAI safety warning", text: "OpenAI issued a warning for one of your users' safety identifiers", lookup: "/v1/safety/cases/", priority: 0, // Normal: a warning, nothing is blocked yet }, "safety_identifier.blocked": { title: "⚠️ Request blocked by OpenAI", text: "A request was blocked", lookup: null, priority: 0, // Normal: a single request was stopped; can be frequent for a bad actor }, } // Table lookup that ignores inherited names such as "toString". function pick(table, key, fallback) { return typeof key === "string" && Object.prototype.hasOwnProperty.call(table, key) ? table[key] : fallback } // Short, safe identifiers only; anything else is left out of the text. function clean(value) { return typeof value === "string" && /^[A-Za-z0-9_.:@-]{1,128}$/.test(value) ? value : null } function handleRequest(request) { const body = request.body && typeof request.body === "object" ? request.body : {} const event = pick(EVENTS, body.type, null) // Guard: only safety events, so other OpenAI events on this integration stay quiet. if (!event) { console.log(`Ignoring OpenAI "${typeof body.type === "string" ? body.type : "unknown"}" event`) return null } const data = body.data && typeof body.data === "object" ? body.data : {} let message if (body.type === "safety_identifier.blocked") { // Documented fields: safety_category (e.g. "bio", "cyber"), safety_identifier, model, project_id. const category = clean(data.safety_category) const user = clean(data.safety_identifier) const model = clean(data.model) message = event.text + (category ? ` (${category})` : "") + (user ? ` for user ${user}` : "") + (model ? ` on ${model}` : "") + "." } else { const id = clean(data.id) message = `${event.text}.` + (id ? ` Look it up with GET ${event.lookup}${id}` : "") } return { title: event.title, message, topic: "OpenAI", priority: event.priority, } } ``` ## OpenAI safety.alert.created webhook payload (sample) ```json { "id": "evt_123", "data": { "id": "alert_0123456789abcdef0123456789abcdef" }, "type": "safety.alert.created", "object": "event", "created_at": 1790668800 } ``` ## FAQ ### Does this work on iPhone and Android? Yes. Install the JustPush app from the App Store or Google Play and sign in. Every phone signed in to your account gets the notification. ### Do I need to write code? No. Install the recipe in Studio, paste your webhook URL into OpenAI and you are done. The code is there if you want to change the text, the sound or the buttons. ### Can I change what the notification says? Yes. After install the recipe's code is yours. Edit it in Studio and test it against the sample payload before you save. ### What does it cost? JustPush is free for 30 days. After that it's $19.99 a year, or $39.99 once. There is no extra charge for recipes.