---
title: "Update a webhook for a workspace"
method: PUT
path: "/workspaces/{workspace}/hooks/{uid}"
tags: ["Workspaces", "Webhooks"]
---

# Update a webhook for a workspace

`PUT /workspaces/{workspace}/hooks/{uid}`

Updates the specified webhook subscription.

The following properties can be mutated:

* `description`
* `url`
* `secret`
* `active`
* `events`

The hook's secret is used as a key to generate the HMAC hex digest sent in the
`X-Hub-Signature` header at delivery time. This signature is only generated
when the hook has a secret.

Set the hook's secret by passing the new value in the `secret` field. Passing a
`null` value in the `secret` field will remove the secret from the hook. The
hook's secret can be left unchanged by not passing the `secret` field in the
request.

## Response `200`

The webhook subscription object.

- WebhookSubscription — A Webhook subscription.
  - `type` string, required
  - `uuid` string — The webhook's id
  - `url` string, uri — The URL events get delivered to.
  - `description` string — A user-defined description of the webhook.
  - `subject_type` 'repository' | 'workspace' — The type of entity. Set to either `repository` or `workspace` based on where the subscription is defined.
  - `subject` Object — Base type for most resource objects. It defines the common `type` element that identifies an object's type. It also identifies the element as Swagger's `discriminator`.
    - `type` string, required
  - `active` boolean
  - `created_at` string, date-time
  - `events` string[] — The events this webhook is subscribed to.
  - `secret_set` boolean — Indicates whether or not the hook has an associated secret. It is not possible to see the hook's secret. This field is ignored during updates.
  - `secret` string — The secret to associate with the hook. The secret is never returned via the API. As such, this field is only used during updates. The secret can be set to `null` or "" to remove the secret (or create a hook with no secret). Leaving out the secret field during updates will leave the secret unchanged. Leaving out the secret during creation will create a hook with no secret.

## Other responses

- `403` — If the authenticated user does not have permission to update the webhook.
- `404` — If the webhook or workspace does not exist.

---

[API](https://skmtc.net/atlassian/apis/bitbucket-api.md) · [All operations](https://skmtc.net/atlassian/apis/bitbucket-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/atlassian/bitbucket-api/versions/8c7911c0a910/schema)
