API Referencev1

Webhooks API

Create, update, test and rotate webhook endpoints and inspect and retry deliveries.

Updated 07/10/2026

On this page

All paths start with /api/developer-portal/apps/:appId/webhooks and need a session token. Changes need the webhooks.manage permission.

MethodPathBody and notes
GET/Endpoints for the application
POST/{name, url, environment?, eventTypes[]}. Returns the endpoint and its secret, shown once.
PATCH/:endpointId{name?, url?, status: active or disabled, eventTypes?}
DELETE/:endpointIdDisables the endpoint
POST/:endpointId/secret/rotateReturns a new secret, shown once
POST/:endpointId/test{eventType?, payload?}. Queues a test delivery (default sandbox.test). Limited to 20 a minute.
GET/:endpointId/deliveriesThe 100 most recent deliveries
POST/:endpointId/deliveries/:deliveryId/retryRetries a failed or dead_lettered delivery with 5 more attempts

Endpoint fields

FieldNotes
name1–120 characters
urlHTTPS; public addresses only; no credentials or secret-like query parameters
environmentsandbox (default). live returns 403 until live webhooks are enabled.
eventTypes1–20 of sandbox.test, policy.quote.created, policy.bound, claim.submitted, payment.completed
status, healthStatus, consecutiveFailures, lastSuccessAt, lastFailureAtHealth tracking
secretPrefix, secretLast4Identify the current secret without revealing it

Delivery fields

FieldNotes
id, eventId, eventType, environmentIdentity
statusIncludes delivered, failed and dead_lettered
attempt, maxAttempts, nextAttemptAtRetry state
firstAttemptAt, completedAtTiming
statusCode, durationMsThe last response
requestBody, responseBodyBodies (responses up to 64 KB)
errorSummary, attempts[]Failure detail

For the payload format, signature verification and retry schedule, see Webhooks.

Need a hand?

Ask Nexra AI for implementation steps or error guidance.

Ask Nexra AI