> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kosli.com/llms.txt
> Use this file to discover all available pages before exploring further.

# kosli_notification_config resource

> Manages where Kosli sends one type of notification that Kosli raises itself, such as API key expiry warnings.

Manages where Kosli sends one type of notification that Kosli raises itself, such as API key expiry warnings. The configured targets replace the recipients Kosli would otherwise derive from what the notification is about.

<Note>
  An organization has at most one configuration per `notification_type`. Creating this resource replaces any configuration already set for that type (for example, through the Kosli UI). Destroying it removes the configuration, so Kosli derives the recipients again. Requires a service account with **Admin** permissions.
</Note>

To read the current configuration and delivery status, use the [`kosli_notification_config` data source](/terraform-reference/data-sources/notification_config).

## Example usage

```terraform theme={"theme":"dracula","languages":{"custom":["/languages/rego.json"]}}
terraform {
  required_providers {
    kosli = {
      source = "kosli-dev/kosli"
    }
  }
}

# Send API key expiry warnings to the platform team instead of the recipients
# Kosli derives by default. Set at least one of emails, slack_webhooks or
# webhooks; destroying the resource restores the derived recipients.
resource "kosli_notification_config" "api_key_expiry" {
  notification_type = "api_key_expiry"

  emails = [
    "platform-team@example.com",
    "security@example.com",
  ]

  # Webhook URLs are secrets: in real configurations pass them in through a
  # sensitive variable rather than committing them.
  slack_webhooks = ["https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXX"]
  webhooks       = ["https://ops.example.com/kosli/notifications"]
}
```

## Notification types

| Value | Notification |
| - | - |
| `api_key_expiry` | A service account API key is about to expire |

## Targets

Each target attribute takes one or more values. You must set at least one of them.

* The provider sends every address in `emails` as a single email target.
* The provider sends each URL in `slack_webhooks` or `webhooks` as its own target.
* Kosli lowercases the host of webhook URLs and the domain of email addresses, and strips trailing slashes from URLs. When Kosli stores an equivalent value, the provider keeps the spelling from your configuration, so this normalization never shows up as a diff.
* URL paths and email local parts are compared exactly.

## Import

Notification configs can be imported using their notification type:

```shell theme={"theme":"dracula","languages":{"custom":["/languages/rego.json"]}}
# Import an existing notification config by its notification type
terraform import kosli_notification_config.api_key_expiry api_key_expiry
```

## Schema

### Required

* `notification_type` (String) The type of notification to configure. Currently `api_key_expiry` (warnings that a service account API key is about to expire). Changing this will force recreation of the resource.

### Optional

* `emails` (Set of String) Email addresses the notification is sent to.
* `slack_webhooks` (Set of String, Sensitive) Slack incoming webhook URLs the notification is posted to. Must use HTTPS.
* `webhooks` (Set of String, Sensitive) Generic webhook URLs the notification is POSTed to as JSON (payload version `1.0`). Must use HTTPS.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.