List webhook endpoints
Returns a paginated list of the org's outbound webhook endpoints.
query Parameters
limitPage size. Values above the server-side cap are clamped (standard default 50, cap 200; a few document-heavy lists use larger windows). Invalid values fall back to the default.
cursorOpaque continuation token from the previous response's pagination.cursor. Omit for the first page. Cursors are stateless and do not expire, but are only valid for the list and filters that produced them.
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
List webhook endpoints › Responses
OK
Create a webhook endpoint
Creates a new outbound webhook endpoint. Every delivery is signed, so the endpoint is always bound to a signing secret: pass secret_id to reuse an existing one, or omit it and a whsec_ secret is provisioned for this endpoint. A provisioned key is returned once as signing_key and is never retrievable again - store it now, or rotate the secret later to get a new one.
Headers
Idempotency-KeyUnique key that makes this POST safe to retry: repeats with the same key replay the first response instead of re-executing. Replays are scoped to the retrying principal (same API key / user) and kept for 24 hours. Required on every POST.
Client-generated idempotency key (e.g. a UUID).
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Create a webhook endpoint › Request Body
event_typesurldescriptionsecret_idsigning_methodCreate a webhook endpoint › Responses
Created
List subscribable webhook event types
Returns the curated, documented set of event types an endpoint may subscribe to - the same allowlist create/update validation enforces. Each entry carries its family and, where the event also backs a mail anchor, the code-owned anchor class (transactional, service_lifecycle or promotional). Read this to build a subscription UI without guessing event names.
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
List subscribable webhook event types › Responses
OK
Delete a webhook endpoint
path Parameters
idWebhook endpoint UUID
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Delete a webhook endpoint › Responses
No Content
Update a webhook endpoint
Partially updates a webhook endpoint (URL, description, event_types, status, secret_id). secret_id can be swapped for another secret in the same organization but never removed - signing is mandatory. The former clear_secret flag is gone and is now rejected as an unknown field.
path Parameters
idWebhook endpoint UUID
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Update a webhook endpoint › Request Body
descriptionevent_typessecret_idstatusurlUpdate a webhook endpoint › Responses
OK
List webhook delivery attempts for an endpoint
Returns delivery attempts (delivered, failed, pending, exhausted) newest first, cursor-paginated (default 50, max 200 per page). has_more is the authoritative continuation signal — it used to be hardcoded false, so a full window was indistinguishable from the end of the endpoint's history. ?sort= accepts created_at with an optional :asc/:desc suffix; a cursor is bound to the ordering that issued it.
path Parameters
idWebhook endpoint UUID
query Parameters
limitPage size. Values above the server-side cap are clamped (standard default 50, cap 200; a few document-heavy lists use larger windows). Invalid values fall back to the default.
cursorOpaque continuation token from the previous response's pagination.cursor. Omit for the first page. Cursors are stateless and do not expire, but are only valid for the list and filters that produced them.
sortOrdering: created_at, with an optional :asc/:desc suffix (default created_at:desc). An unknown value is rejected. Cursors are bound to the ordering that issued them, so changing sort mid-walk needs a fresh first page.
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
List webhook delivery attempts for an endpoint › Responses
OK
Manually requeue a webhook delivery
Flips the delivery back into 'failed' state with next_retry_at=now so the retry sweep picks it up immediately. Use to recover from a customer endpoint outage that has since cleared.
path Parameters
idWebhook endpoint UUID
delivery_idDelivery UUID
Headers
Idempotency-KeyUnique key that makes this POST safe to retry: repeats with the same key replay the first response instead of re-executing. Replays are scoped to the retrying principal (same API key / user) and kept for 24 hours. Required on every POST.
Client-generated idempotency key (e.g. a UUID).
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Manually requeue a webhook delivery › Responses
Accepted