API Referencev1
Webhooks API
Create, update, test and rotate webhook endpoints and inspect and retry deliveries.
Updated 07/10/2026
On this page
All paths start with /api/developer-portal/apps/:appId/webhooks and need a session token. Changes need the webhooks.manage permission.
| Method | Path | Body and notes |
|---|---|---|
GET | / | Endpoints for the application |
POST | / | {name, url, environment?, eventTypes[]}. Returns the endpoint and its secret, shown once. |
PATCH | /:endpointId | {name?, url?, status: active or disabled, eventTypes?} |
DELETE | /:endpointId | Disables the endpoint |
POST | /:endpointId/secret/rotate | Returns a new secret, shown once |
POST | /:endpointId/test | {eventType?, payload?}. Queues a test delivery (default sandbox.test). Limited to 20 a minute. |
GET | /:endpointId/deliveries | The 100 most recent deliveries |
POST | /:endpointId/deliveries/:deliveryId/retry | Retries a failed or dead_lettered delivery with 5 more attempts |
Endpoint fields
| Field | Notes |
|---|---|
name | 1–120 characters |
url | HTTPS; public addresses only; no credentials or secret-like query parameters |
environment | sandbox (default). live returns 403 until live webhooks are enabled. |
eventTypes | 1–20 of sandbox.test, policy.quote.created, policy.bound, claim.submitted, payment.completed |
status, healthStatus, consecutiveFailures, lastSuccessAt, lastFailureAt | Health tracking |
secretPrefix, secretLast4 | Identify the current secret without revealing it |
Delivery fields
| Field | Notes |
|---|---|
id, eventId, eventType, environment | Identity |
status | Includes delivered, failed and dead_lettered |
attempt, maxAttempts, nextAttemptAt | Retry state |
firstAttemptAt, completedAt | Timing |
statusCode, durationMs | The last response |
requestBody, responseBody | Bodies (responses up to 64 KB) |
errorSummary, attempts[] | Failure detail |
For the payload format, signature verification and retry schedule, see Webhooks.