Send a signed test event to the webhook URL
- In the sandbox
In plain words
The body has event_id, type (always test), occurred_at and message, signed like a status event. It reports no invoice. Since 0.16.0 any query parameter answers 400.
apiKeyAuthorizationBearer <token>Send your key as a bearer token: Authorization: Bearer <your-api-key>. Health is the only call that needs no key.
What the partner's endpoint answered.
application/json- response
delivered*booleanhttp_status*integer|nullduration_ms*integercurl -X POST "https://example.com/webhook/test" \ -H "Authorization: Bearer <your-api-key>"{ "delivered": true, "http_status": 0, "duration_ms": 0}Set the webhook URL, or rotate its secret PUT
The operator's key sets the operator's webhook, which gets every client's events; a client's admin key sets that client's own, which gets only its events. The first call needs url and creates the secret, which is returned once. Rotating returns the new secret once. For 24 hours the service signs each delivery with both the new and the old secret, so the partner can switch without losing events. Only events written after the first call are delivered. The URL must be https, and every address its host resolves to must be public: loopback, private, link-local, carrier-grade NAT, multicast, reserved and cloud metadata addresses are refused, here and again before each delivery. Redirects are not followed. Since 0.16.0 any query parameter answers 400, so a misspelt client can never change the operator's own webhook.
The hosted sandbox, and how to ask for a key.