Docs

Set the webhook URL, or rotate its secret

  • In the sandbox

In plain words

Sets the address that receives status events, or rotates its secret.
PUT
/webhook

The operator's key sets the operator's webhook, which gets every client's events; a client's admin key sets that client's own, which gets only its events. The first call needs url and creates the secret, which is returned once. Rotating returns the new secret once. For 24 hours the service signs each delivery with both the new and the old secret, so the partner can switch without losing events. Only events written after the first call are delivered.

The URL must be https, and every address its host resolves to must be public: loopback, private, link-local, carrier-grade NAT, multicast, reserved and cloud metadata addresses are refused, here and again before each delivery. Redirects are not followed.

Since 0.16.0 any query parameter answers 400, so a misspelt client can never change the operator's own webhook.

Authorization

apiKey
headerAuthorizationBearer <token>

Send your key as a bearer token: Authorization: Bearer <your-api-key>. Health is the only call that needs no key.

Request body

application/json
  1. body
url?string
Match^https://
Formaturi
active?boolean
rotate_secret?boolean
Defaultfalse
contact_email?|
Lengthlength <= 254

Response body

Saved.

application/json
  1. response
url*|
Match^https://
Formaturi
active*boolean
secret_rotated_at?|
Formatdate-time
contact_email?|

Who to tell when deliveries die.

last_delivery?|null
secret?string

Present only when a secret was created or rotated in this call.

curl -X PUT "https://example.com/webhook" \  -H "Authorization: Bearer <your-api-key>" \  -H "Content-Type: application/json" \  -d '{}'
{  "url": "http://example.com",  "active": true,  "secret_rotated_at": "2019-08-24T14:15:22Z",  "contact_email": "string",  "last_delivery": {    "at": "2019-08-24T14:15:22Z",    "http_status": 0  },  "secret": "string"}