Create a webhook endpoint

POST
/v1/webhooks

secret (an HMAC-SHA256 signing key, whsec_...) is generated server-side and returned only in this response — it is never shown again (subsequent GET /v1/webhooks calls return an empty secret). Rejected once the tenant is at its plan's max_webhooks cap (a defence-in-depth limit — the events pipeline fans out one subrequest per active webhook per event).

Authorization

bearerAuth
headerAuthorizationBearer <token>

API key sent as Authorization: Bearer <key>. Looked up by SHA-256 hash (email_core::sha256_hex) against api_keys.hash; revoked keys and keys belonging to a suspended tenant are rejected. See the top-level Authentication section for permission levels.

Request Body

application/json
  1. body
url*string

Must start with https://.

Formaturi
events?array<>

Event types to subscribe to. Omit (or send []) to receive all of them.

Response Body

Created — secret is shown exactly once.

application/json
  1. response

The creation response — the only place secret is ever shown, and the only place events is a JSON array.

id?string
url?string
Formaturi
events?array<>
secret?string

HMAC-SHA256 signing secret (whsec_...). Shown only here.

curl -X POST "https://example.com/v1/webhooks" \  -H "Content-Type: application/json" \  -d '{    "url": "http://example.com"  }'
{  "id": "string",  "url": "http://example.com",  "events": [    "delivery"  ],  "secret": "string"}