The health endpoint
Moatline learns two things from a site's live URL when it answers JSON: which commit is deployed and whether its configuration works. Both are optional — without them the URL is still checked for being up.
Format
json
{
"ok": true,
"commit": "3f2c1ab9e4d7…",
"checks": {
"email": true,
"storage": true,
"database": true,
"mailFailures": 0,
"lastMailAt": "2026-10-04T11:02:00Z"
}
}commit— the git SHA the running build was made from. Also read fromcommitSha,commit_sha,sha,gitCommit,git_commit,revisionorversion(top level only). With it, Moatline scans exactly what is deployed, rescans when it changes and knows when a deploy went live. Without it, a linked Dokploy application's last successful deploy is used.checks— the app's own report on its configuration: up to 30 keys, each a boolean, a number or a short string (≤ 100 characters). Never put secret values here — only whether something is set and works. A check that turnsfalsesends a notification; the repository page shows them under Configuration.
Next.js example
ts
// app/api/health/route.ts
export const dynamic = "force-dynamic";
export function GET() {
return Response.json({
ok: true,
commit: process.env.GIT_COMMIT_SHA ?? null,
checks: {
email: !!(process.env.RESEND_API_KEY || process.env.SMTP_HOST),
storage: !!process.env.S3_BUCKET,
serverActionsKey: !!process.env.NEXT_SERVER_ACTIONS_ENCRYPTION_KEY,
},
});
}Set GIT_COMMIT_SHA at build time — on Dokploy and Coolify a build argument from the platform's commit variable, in GitHub Actions ${{ github.sha }}.
Point the repository's live URL at this endpoint (e.g. https://example.com/api/health); performance runs and the security probe still test the site's root page.