Skip to main content
POST
Confirm your deployment before running this request. This page describes an API contract; a published reference does not establish hosted availability. Check the dated host report and obtain your deployment URL and credentials. Replace the example host if your provisioned service uses a different URL.
Register a durable webhook endpoint. Returns the signing secret exactly once on creation. Subsequent reads omit it; if you lose it or want to roll a leaked secret, call POST /webhooks/{id}/rotate-secret — it preserves the delivery history and only changes the signing secret.

Request body

CreateWebhookEndpointRequest
string
required
Receiver URL. Must start with http:// or https://; ≤2048 chars.
string[]
Events to subscribe to. Either explicit names (‘job.completed’, ‘job.failed’) or ’*’ for all.

Response

WebhookEndpointWithSecret
string
required
string
required
string[]
required
boolean
required
string
required
string
required
string
required
HMAC-SHA256 signing secret. Compare incoming X-Webhook-Signature against HMAC(secret, f'{t}.{body}').

Status codes

Using this contract

Read the source OpenAPI document for declared schemas and alternatives. This page also includes documented corrections from the spec overlays. Example IDs and values are illustrative; replace them with records from your workspace.
Last modified on September 21, 2026