Create a webhook endpoint
secret (an HMAC-SHA256 signing key, whsec_...) is generated server-side and returned only in this response — it is never shown again (subsequent GET /v1/webhooks calls return an empty secret). Rejected once the tenant is at its plan's max_webhooks cap (a defence-in-depth limit — the events pipeline fans out one subrequest per active webhook per event).
bearerAuthAuthorizationBearer <token>API key sent as Authorization: Bearer <key>. Looked up by SHA-256
hash (email_core::sha256_hex) against api_keys.hash; revoked
keys and keys belonging to a suspended tenant are rejected. See the
top-level Authentication section for permission levels.
application/json- body
url*stringMust start with https://.
urievents?array<>Event types to subscribe to. Omit (or send []) to receive all of them.
Created — secret is shown exactly once.
application/json- response
The creation response — the only place secret is ever shown, and the only place events is a JSON array.
id?stringurl?stringurievents?array<>secret?stringHMAC-SHA256 signing secret (whsec_...). Shown only here.
curl -X POST "https://example.com/v1/webhooks" \ -H "Content-Type: application/json" \ -d '{ "url": "http://example.com" }'{ "id": "string", "url": "http://example.com", "events": [ "delivery" ], "secret": "string"}