Create a webhook endpoint
An HTTPS URL we push events to, signed with the endpoint’s
secret (Standard Webhooks), which the response carries. The
endpoint receives the events of every subscription that names it,
plus the platform events its events patterns match (such as
job.*), for namespaces its namespace_prefix covers. With no
events, only subscriptions send it anything.
Needs a read_write key. namespace_prefix defaults to the key’s
scope and must lie inside it. An organization has as many endpoints
as its plan allows; one more is plan_required.
Authorizations
An organization API key. Keys carry a role (read_write or
read_only) and may be restricted to a namespace prefix such as
acme/*, or to one namespace such as acme/prod/tenant_1. A prefix
matches on a / boundary: acme/prod/tenant_1* covers
acme/prod/tenant_1 and everything under acme/prod/tenant_1/,
never acme/prod/tenant_12.
Headers
One key per logical request, reused only on its retries. A key
belongs to one request: within your organization, the same method,
path, query and body. For 24 hours after a successful response, a
request with the key and the same body gets that response back
verbatim, with Idempotent-Replayed: true, and runs nothing. Only a
successful response is kept, so the retry of a request that failed
runs again. While the first request runs or its response is kept,
the key with a different request is idempotency_key_reused (422).
A request sent while one with its key is still running is
rate_limited with Retry-After: 1, without running: retry it to
get the first one's response. In the rare case the key can't be
checked, the request runs as if it had none.
1 - 255Body
An https:// URL with no user or password. It must resolve to a public address at every delivery. A host that is plainly private (a non-public address, localhost, a name with no dot, or a name under a private-use suffix such as .internal or .local) is refused with invalid_request.
2048^https://An event type such as job.completed, or a family with * after the dot, such as job.*.
64^[a-z_]+\.([a-z_]+|\*)$Which namespaces' events it receives. Defaults to the key's scope, and must lie inside it.
1 - 257^(\*|[A-Za-z0-9._:/-]+\*?)$256Response
Created, with its secret.
^we_[0-9a-z]{26}$The platform event types it receives, besides the events of subscriptions that name it.
An event type such as job.completed, or a family with * after the dot, such as job.*.
64^[a-z_]+\.([a-z_]+|\*)$Which namespaces, written as an API key's scope: * for the whole
organization, a prefix such as acme/staging/ or acme/*, or one
namespace. A prefix matches on a / boundary.
1 - 257^(\*|[A-Za-z0-9._:/-]+\*?)$active: delivering. failing: no successful delivery for 24 hours
and at least 10 failed attempts; still delivering, and owners and
admins were emailed. disabled: after 5 days without a success, or
by enabled: false; deliveries are skipped until it is enabled.
active, failing, disabled When the current run of failed attempts began, the first failure after the last success; null once an attempt succeeds. Failing and disabled count from it.
The most deliveries a second it is sent; null for no limit beyond 16 in flight at once.
When the secret before the last rotation stops signing; null when only one secret signs.
RFC 3339, UTC.
RFC 3339, UTC.
On create, on rotation, and on a get with a read_write key; absent otherwise.
^whsec_[A-Za-z0-9+/]{43}=$