1. OpenAPI (Demo)
  2. Webhooks
  3. Create a webhook subscription
ReadmeGitHub
  • Platform API overview
  • Quickstart
  • POSTCreate a member session
  • POSTRefresh a member session
  • DELETERevoke a member session
  • GETList organizations
  • POSTCreate an organization
  • GETGet an organization
  • PATCHUpdate an organization
  • GETList organization members
  • POSTInvite an organization member
  • DELETERemove an organization member
  • PATCHUpdate a member role
  • GETList projects
  • POSTCreate a project
  • GETGet a project
  • DELETEArchive a project
  • PATCHUpdate a project
  • GETList project environments
  • POSTCreate a project environment
  • GETList project documents
  • POSTCreate a project document
  • GETGet a document
  • DELETEArchive a document
  • PATCHUpdate a document
  • POSTPublish a document
  • GETList contacts
  • POSTCreate a contact
  • GETGet a contact
  • DELETEDelete a contact
  • PATCHUpdate a contact
  • GETList product events
  • GETGet analytics overview
  • GETList workflows
  • POSTCreate a workflow
  • GETList workflow runs
  • GETList webhook subscriptions
  • POSTCreate a webhook subscription
  • GETGet a webhook subscription
  • DELETEDelete a webhook subscription
  • PATCHUpdate a webhook subscription
  • GETList webhook deliveries
  • POSTReplay a webhook delivery
  • GETList files
  • POSTCreate a multipart file upload
  • GETGet file metadata
  • DELETEDelete a file
  • GETGet current subscription
  • PATCHUpdate subscription settings
  • GETList invoices
  • GETGet metered usage
  • GETList API keys
  • POSTCreate an API key
  • POSTRevoke an API key
  • GETList audit logs
  • GETList exports
  • POSTCreate an export
  • GETGet API health
POST/organizations/{organizationId}/webhooks

Create a webhook subscription

Registers an HTTPS endpoint for selected events and returns the signing secret once.

Send request

Use the documented inputs to call this endpoint directly.

API serverbase URL
Bearer tokenBearerAuthoptional
Stored only in this browser for the BearerAuth security scheme and reused on every API page in this group.

Parameters

Values are applied to the request and the example on the right.

organizationIdpath · stringrequired

Opaque organization identifier.

Idempotency-Keyheader · string · uuidoptional

Unique key for retry-safe writes, retained for 24 hours.

Request body

application/jsonrequired
urlstring · urirequired
descriptionstringoptional
eventsarray<string>required
metadataobjectoptional

Responses

201application/json

Subscription created.

{
  "id": "whk_01J8FD1M5T7Q9P2V4K6",
  "url": "https://hooks.acme.example/heyo",
  "description": "Acme production event receiver",
  "events": [
    "contact.created"
  ],
  "status": "active",
  "signing_secret_last4": "4K6Z",
  "delivery_health": {
    "success_rate": 99.5,
    "failed_last_24h": 1,
    "last_delivery_at": "2026-09-03T11:05:00Z"
  },
  "created_at": "2026-06-17T12:12:00Z",
  "signing_secret": "whsec_demo_01J8FG8N2P5Q7T4V6M9"
}
422

Webhook URL or event names are invalid.

List webhook subscriptions< PreviousGet a webhook subscriptionNext >

Powered by heyo

curl --request POST \  'https://api.demo.heyo.example/v3/organizations/org_01J8F1Q6N6VTX4E8W9R2D0A7B3/webhooks' \  --header 'Idempotency-Key: 5ba89923-8c6d-44a3-9ab7-2fbbdb865f9a' \  --header 'Content-Type: application/json' \  --data '{  "url": "https://hooks.acme.example/heyo",  "description": "Acme production event receiver",  "events": [    "contact.created",    "document.published",    "export.failed"  ],  "metadata": {    "team": "platform",    "service": "event-ingest"  }}'
{  "id": "whk_01J8FD1M5T7Q9P2V4K6",  "url": "https://hooks.acme.example/heyo",  "description": "Acme production event receiver",  "events": [    "contact.created"  ],  "status": "active",  "signing_secret_last4": "4K6Z",  "delivery_health": {    "success_rate": 99.5,    "failed_last_24h": 1,    "last_delivery_at": "2026-09-03T11:05:00Z"  },  "created_at": "2026-06-17T12:12:00Z",  "signing_secret": "whsec_demo_01J8FG8N2P5Q7T4V6M9"}