Skip to main content
POST
Create a webhook endpoint

Authorizations

Authorization
string
header
required

An organization API key. Keys carry a role (read_write or read_only) and may be restricted to a namespace prefix such as acme/*, or to one namespace such as acme/prod/tenant_1. A prefix matches on a / boundary: acme/prod/tenant_1* covers acme/prod/tenant_1 and everything under acme/prod/tenant_1/, never acme/prod/tenant_12.

Headers

Idempotency-Key
string

One key per logical request, reused only on its retries. A key belongs to one request: within your organization, the same method, path, query and body. For 24 hours after a successful response, a request with the key and the same body gets that response back verbatim, with Idempotent-Replayed: true, and runs nothing. Only a successful response is kept, so the retry of a request that failed runs again. While the first request runs or its response is kept, the key with a different request is idempotency_key_reused (422). A request sent while one with its key is still running is rate_limited with Retry-After: 1, without running: retry it to get the first one's response. In the rare case the key can't be checked, the request runs as if it had none.

Required string length: 1 - 255

Body

application/json
url
string<uri>
required

An https:// URL with no user or password. It must resolve to a public address at every delivery. A host that is plainly private (a non-public address, localhost, a name with no dot, or a name under a private-use suffix such as .internal or .local) is refused with invalid_request.

Maximum string length: 2048
Pattern: ^https://
events
string[]

An event type such as job.completed, or a family with * after the dot, such as job.*.

Maximum string length: 64
Pattern: ^[a-z_]+\.([a-z_]+|\*)$
namespace_prefix
string

Which namespaces' events it receives. Defaults to the key's scope, and must lie inside it.

Required string length: 1 - 257
Pattern: ^(\*|[A-Za-z0-9._:/-]+\*?)$
description
string
Maximum string length: 256
max_per_second
number

Response

Created, with its secret.

id
string
required
Pattern: ^we_[0-9a-z]{26}$
url
string<uri>
required
description
string
required
events
string[]
required

The platform event types it receives, besides the events of subscriptions that name it.

An event type such as job.completed, or a family with * after the dot, such as job.*.

Maximum string length: 64
Pattern: ^[a-z_]+\.([a-z_]+|\*)$
namespace_prefix
string
required

Which namespaces, written as an API key's scope: * for the whole organization, a prefix such as acme/staging/ or acme/*, or one namespace. A prefix matches on a / boundary.

Required string length: 1 - 257
Pattern: ^(\*|[A-Za-z0-9._:/-]+\*?)$
status
enum<string>
required

active: delivering. failing: no successful delivery for 24 hours and at least 10 failed attempts; still delivering, and owners and admins were emailed. disabled: after 5 days without a success, or by enabled: false; deliveries are skipped until it is enabled.

Available options:
active,
failing,
disabled
failing_since
string<date-time> | null
required

When the current run of failed attempts began, the first failure after the last success; null once an attempt succeeds. Failing and disabled count from it.

max_per_second
number | null
required

The most deliveries a second it is sent; null for no limit beyond 16 in flight at once.

previous_secret_expires_at
string<date-time> | null
required

When the secret before the last rotation stops signing; null when only one secret signs.

stats
object
required
created_at
string<date-time>
required

RFC 3339, UTC.

updated_at
string<date-time>
required

RFC 3339, UTC.

secret
string

On create, on rotation, and on a get with a read_write key; absent otherwise.

Pattern: ^whsec_[A-Za-z0-9+/]{43}=$