Skip to content
n8n recipe

Domain Health Hub alerts as HaloPSA tickets

A free n8n recipe that checks each Domain Health Hub alert's signature, then raises a HaloPSA ticket or adds a private note to the open one.

Download the n8n workflowAn n8n recipe, not a native integration. Free to use and change.

What it does

  1. Domain Health Hub posts an alert to the workflow's webhook in n8n.
  2. n8n checks the X-DHH-Signature header against the raw body with your signing secret, and refuses anything unsigned, altered or more than five minutes old (it answers 401).
  3. It looks in HaloPSA for an open ticket titled for the same alert and domain, such as DHH: DNS changed on client.co.uk.
  4. If there is one, it adds a note with the new alert. If not, it raises a ticket for the client, with what changed, when, and a link back to the domain in Domain Health Hub.
  5. Only then does it answer us. If HaloPSA can't be reached, n8n answers with an error and we retry after 1, 5 and 30 minutes, then 2 and 6 hours.

n8n has a HaloPSA node, but it can't set the client on a new ticket or add a note to one, so the recipe calls the HaloPSA API with HTTP Request nodes instead.

Before you start

  • n8n reachable over HTTPS at a public address. We only send webhooks to https:// URLs.
  • A recent n8n: the signature check uses the Crypto node's HMAC with a Crypto credential, added to n8n in 2026. We tested on n8n 2.42.4. On an older n8n, swap in version 1 of the Crypto node and paste the secret into its Secret field instead.
  • Admin access to HaloPSA, to create the API credentials below.
  • An owner login for your Domain Health Hub workspace, to add the webhook.

Set it up

  1. Download dhh-alerts-halopsa.json and, in n8n, choose Import from file on a new workflow.
  2. In Domain Health Hub, go to Alerts, add a webhook with the workflow's Production URL (from its DHH alert node), and copy the signing secret it shows you. It's shown once.
  3. In n8n, open the HMAC-SHA256 node, create a Crypto credential and paste the secret into Hmac Secret.
  4. For the Find open ticket, Add note and Create ticket nodes: In HaloPSA, add an API application (Configuration, Integrations, Halo API) using Client ID and Secret, with permission to read and edit tickets. In n8n, create an OAuth2 API credential: grant type Client Credentials, Access Token URL https://YOURTENANT.halopsa.com/auth/token (your Halo address), scope all, and the application's Client ID and Secret.
  5. Open the Ticket details node and fill in the settings at the top (below).
  6. Activate the workflow. In Domain Health Hub, choose Send test event on the webhook: a ticket called DHH: Test alert should appear in HaloPSA for your default client. Close it once you've seen it.

Settings

At the top of the Ticket details node. Client names are matched exactly as they appear in Domain Health Hub; anything unmapped goes to the default.

SettingWhat to put
baseUrlYour Halo address, such as https://acme.halopsa.com
ticketTypeIdThe ticket type to raise, by ID
defaultClientIdThe Halo client a ticket goes to when its client isn't mapped
clientIdsDomain Health Hub client names mapped to Halo client IDs
noteOutcomeThe action outcome for notes. Private Note unless yours is called something else

The HaloPSA API calls it makes

StepRequest
Find an open ticket with the same titleGET /api/Tickets?search=…&open_only=true
Add a private note to itPOST /api/Actions
Or raise a new ticketPOST /api/Tickets

What it can't do

  • It's an n8n recipe, not a native integration: you run it, on your n8n, and we don't support changes you make to it.
  • It only works one way. Closing the ticket in HaloPSA doesn't change anything in Domain Health Hub, and a problem that clears doesn't close the ticket.
  • We ran it end to end in n8n against a stand-in for the HaloPSA API, built from the documentation below. We haven't run it against a live HaloPSA account, so try it on a test client first.
  • If the ticket is saved but our request times out before n8n answers, we send the alert again, and you'll get a note on the same ticket rather than a new one.
  • Notes are added as hidden actions with the outcome you name; Halo refuses an action whose outcome doesn't exist.
  • The search runs on Halo's own matching, then the workflow keeps only an exact title match.

Sources

Each HaloPSA call was checked against the vendor's documentation:

And the n8n nodes it uses:

Other PSAs: see every recipe.

Get alerts worth raising a ticket for.

Start a free 28-day trial: up to 3 domains, no card needed.