Agents and teams · Testers, servers and webhooks

Docs › Agents and teams

Testers, servers and webhooks

Testers send a zip or post to a shared server, and webhooks tell Slack, Discord or Teams.

Test mode: testers send you a zip#

<Notato mode="test" project="checkout-web" appVersion={import.meta.env.VITE_APP_VERSION} />

Testers annotate, then press Package: a zip downloads with feedback.md (annotations in order, with inline screenshots), annotations.json, and shots/. Their work survives a reload. Give your agent the zip:

notato_import_bundle { path: "~/Downloads/notato-checkout-web-20261005-1042.zip" }

Or add server="https://notato.example.com" token="notato_…" and the zip is uploaded as well. Input fields are masked in screenshots by default in test and agent mode, and password fields always; data-notato-mask="false" opts a field out. Mark anything else private with data-notato-mask: it is covered in screenshots and none of its text, or the text of anything inside it, is recorded. What is typed into a field is never recorded as text. The mobile SDKs follow the same rules (Feedback.Mask in .NET MAUI, .notatoMask() in SwiftUI, Notato.mask(view) and Modifier.notatoMask() on Android).

Shared server#

For testers on other machines, run one server:

NOTATO_ADMIN_PASSWORD=… npx notato serve --host 0.0.0.0 --trust-proxy

Put a TLS-terminating reverse proxy in front. It serves the board UI at / (sign in as admin), the API, and MCP over HTTP at /mcp.

Docker (data in a volume):

docker run -p 4747:4747 -v notato:/data -e NOTATO_ADMIN_PASSWORD=… ghcr.io/notatorg/notato
VariableMeaning
NOTATO_HOST, NOTATO_PORT, NOTATO_DIRBind address (default 127.0.0.1), port (4747), data directory (./.notato)
NOTATO_ADMIN_USER, NOTATO_ADMIN_PASSWORDAdmin account. The password is applied on every start; if unset, one is generated and printed once
NOTATO_TRUST_PROXY=1Believe X-Forwarded-For and X-Forwarded-Proto from your proxy
NOTATO_CORS_ORIGINS, NOTATO_ALLOWED_HOSTSComma-separated origins / Host names
NOTATO_CONFIG, NOTATO_SCREENSHOTSSettings file (default ./notato.config.json); on/off overrides the file. See Screenshots
NOTATO_MCPoff refuses agents whatever the file says. See MCP over HTTP
NOTATO_PROJECTnotato dev: the projects this agent works on, comma-separated. See Several repositories

Webhooks#

The server can tell other systems when an annotation is created or changes, such as a Slack or Discord channel, a build hook, your own service:

npx notato config webhook add https://hooks.slack.com/services/T000/B000/XXXX --format slack --event resolved
npx notato config webhook add https://ci.example.com/notato --secret env:NOTATO_HOOK_SECRET
npx notato config webhook                  # list them
npx notato config webhook test ci.example.com   # send a sample now, and see what the other end said

Or on the board, under Settings › Webhooks: pick Slack, Discord, Teams or JSON, paste the URL, choose the project and the events, add a signing secret for JSON, and save. Test (or Preview and test… while editing, before you save) lets you pick an event and a real note (or a made-up one), shows the message exactly as it will go out (the Teams card drawn as Teams shows it, the chat line, or the JSON and its headers) and says what is left out and why, then Send this test sends that very message and shows what the other end answered (the HTTP status, how long it took and what it said back). The board writes the same file, never shows a saved URL or a secret written in the file again (it shows https://hooks.slack.com/services/•••• and "a secret is set"; replace them to change them), and refuses an edit made to a copy that has since changed in another tab or with notato config.

They live in notato.config.json ("webhooks": [{ "url": …, "events": […], "format": "json", "secret": "env:NAME", "name": …, "project": … }]), so they can be committed, and a running server picks a change up on the next event. Events: annotation.created, acknowledged, variants_ready, variant_chosen, resolved, revert_requested, reverted, dismissed, reopened, updated, replied, deleted; leave events out for all of them.

Settings, and working with other people#

The gear on the toolbar opens a panel of settings for you, kept in this browser:

Setting
Your nameWritten on your notes, replies and picks, so others can tell who wrote what
Copy as MarkdownThe level the toolbar's copy button writes at
Component names, Computed stylesWhether to record them with each note
ScreenshotsWhether to take one with each note. The server's own setting wins: where it has them off this is switched off and says so
Only my notesHide what other people wrote on this page (needs your name)
Pin colourThe colour of a pin nobody has acted on yet. Seven choices, none of them a colour a status already means
Hide Notato until this page is reloadedGets it out of the way; the annotate shortcut brings it back

Server and agent shows whether the page is connected, the server's version and how many pages are connected, and which coding agents are connected and whether one is watching (with how to set Notato up for one when none is). A page knows only where the server is: webhooks are set up on the server, in its config file or with npx notato config webhook, and a page never sees them.

Several people can annotate one project, each in their own browser with their own name. When more than one person has notes on a page, each pin carries its author's initials in a colour taken from their name, and a card shows who wrote what. The board has a Person filter, notato export --by "Sam" and ?by= on the API write only one person's notes, and a pick or a reply is attributed to whoever made it. This is attribution, not accounts: a shared server still has one admin login and project tokens, and anyone with a project's token can write as any name.