v8

OpenAPI 3.1.02026-08-033623795.0 MB
Webhooks

Create Webhook

Creates a webhook endpoint that receives event notifications via HTTP POST.

post/webhooks

Headers

Idempotency-Keystring
Example:d9105228-4a08-46b1-8b91-42fed586d383

A unique key that makes this request safe to retry. See Idempotent requests.

Request body

api_version'v1' | 'v2' | 'v5'

The API version for this webhook. Defaults to v2.

api_version_datestring nullable

The dated API version (Api-Version-Date) to pin this webhook's payloads to. Only valid for v1 webhooks. Omit to leave the webhook unpinned, tracking the current payload shape.

child_resource_eventsboolean

Whether to send events for child resources. For example, if the webhook is created for an account, enabling this sends events only from its connected accounts.

enabledboolean

Whether or not the webhook is enabled. Defaults to true.

eventsstring[]

The events to send the webhook for, in dot form (for example payment.succeeded).

resource_idstring nullable

The account or app to create the webhook for. Defaults to the current account.

urlstring required

The URL to send the webhook to.

Response

webhook created

api_version'v1' | 'v2' | 'v5' required

The API version used to format payloads sent to this webhook endpoint.

api_version_datestring nullable required

The dated API version (Api-Version-Date) that v1 payloads for this endpoint are pinned to: events serialize exactly like a REST read at this version (the native serializer where the resource has one). Null when unpinned — legacy (v2/v5) webhooks, and v1 webhooks on the legacy payload shape.

child_resource_eventsboolean required

Whether events are sent for child resources. For example, if the webhook is on an account, enabling this sends events only from its connected accounts.

created_atstring required

When the webhook was created, as an ISO 8601 timestamp.

enabledboolean required

Whether this webhook endpoint is currently active and receiving events.

eventsstring[] required
idstring required

Webhook ID, prefixed hook_.

resource_idstring required

ID of the resource (account or app) this webhook is attached to.

testable_eventsstring[] required
urlstring required

Destination URL where webhook payloads are delivered via HTTP POST.

webhook_secretstring nullable required

Secret key used to sign webhook payloads for verification. Include this in your HMAC validation logic. Returned on the create response and to interactive dashboard sessions; null for API-key and OAuth callers on later reads.

Example response

{
  "api_version": "v1",
  "events": [
    "invoice.created"
  ],
  "testable_events": [
    "invoice.created"
  ]
}