---
title: "Update a webhook"
method: PUT
path: "/v1/webhooks/{id}"
tags: ["Webhooks"]
---

# Update a webhook

`PUT /v1/webhooks/{id}`

Updates a webhook. Only the fields you send are changed. Sending `auth_password` or `auth_token` replaces the stored value; omitting them leaves it alone. The signing secret is not returned — rotate it if you have lost it.

## Path parameters

- `id` integer, required

## Request body

- PutV1WebhooksId — Update a webhook
  - `url` string — Destination URL. Must be a public http(s) address.
  - `name` string — Label for the webhook.
  - `http_method` 'POST' | 'PUT' | 'PATCH' — HTTP method used to deliver.
  - `failure_only` boolean — Deliver only for failed tests.
  - `alert_types` 'ALL' | 'VIRTUAL' | 'REAL' — Which grid to report on: ALL, VIRTUAL or REAL.
  - `name_filter` string — Glob matched against the test name, falling back to the build identifier.
  - `auth_type` 'NONE' | 'BASIC' | 'BEARER' — How to authenticate against your endpoint.
  - `auth_username` string — Username for BASIC auth. Write-only.
  - `auth_password` string — Password for BASIC auth. Write-only.
  - `auth_token` string — Token for BEARER auth. Write-only.
  - `headers` string[] — Custom request headers, each an object with `key` and `value`. Replaces the existing set.
  - `params` string[] — Custom query parameters, each an object with `key` and `value`. Replaces the existing set.
  - `payload_template` string — Custom JSON body template. Send an empty string to go back to the default payload.

## Response `200`

Update a webhook

- TestingbotEntitiesWebhook — Testingbot_Entities_Webhook model
  - `id` integer, required — Unique numeric webhook ID.
  - `name` string, required — Label for the webhook, shown on the dashboard.
  - `url` string, required — Destination URL. May contain `{{VARIABLES}}`, which are substituted at delivery time.
  - `http_method` string, required — HTTP method used to deliver: POST, PUT or PATCH.
  - `failure_only` boolean, required — When true, only failed tests trigger a delivery.
  - `alert_types` string, required — Which grid the test ran on: ALL, VIRTUAL (VM) or REAL (physical device).
  - `name_filter` string, required — Glob matched against the test name, falling back to the build identifier. Empty means every test.
  - `auth_type` string, required — How the request authenticates against your endpoint: NONE, BASIC or BEARER. The credentials themselves are never returned.
  - `headers` object[], required — Custom request headers, each `{ "key": ..., "value": ... }`. Values support `{{VARIABLES}}`.
  - `params` object[], required — Custom query parameters appended to the URL, each `{ "key": ..., "value": ... }`.
  - `payload_template` string, required — Custom JSON body template. Empty means the default TestingBot payload is sent.
  - `created_at` string, date-time, required — When the webhook was created.
  - `updated_at` string, date-time, required — When the webhook was last changed.
  - `signing_secret` string, required — Secret used to verify the `X-TestingBot-Signature` header. Only present when the webhook is created or its secret is rotated; store it then, because it is never returned again.

## Other responses

- `401` — Authentication required
- `403` — Your role does not permit this action
- `404` — Webhook not found
- `422` — Validation error or unsafe URL

---

[API](https://skmtc.net/testingbot/apis/testingbot-rest-api.md) · [All operations](https://skmtc.net/testingbot/apis/testingbot-rest-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/testingbot/testingbot-rest-api/versions/eff607a49246/schema)
