Skip to main content

Webhooks (Management API)

Register webhook subscriptions to receive real-time notifications for events across your organisation. For webhook payload formats and security, see the Webhooks section.
These endpoints require the notification_subscription permissions: notification_subscription:read to list subscriptions, and notification_subscription:write to create, remove, or send a test webhook. A key without the required permission receives 403 Permission Denied. See Permissions for details.

List Webhook Subscriptions

Retrieve all active webhook subscriptions for your organisation.

Example Request

Response

Register Webhook Subscription

Create a new webhook subscription for your organisation.

Request Body

Available Event Types

Example Request

Response (201 Created)

webhook_secret is returned only in this response. Store it securely: you need it to verify the X-Webhook-Signature header of every delivery. See Webhook Security. Each subscription (target URL and event type) has its own webhook_secret. Verify each delivery with the secret of the subscription it belongs to; the X-Webhook-Event header tells you the event type.

Remove Webhook Subscription

Delete (deactivate) a webhook subscription by specifying the target URL and notification type.
string
required
The webhook target URL
string
required
The notification type to unsubscribe from

Example Request

Returns 204 No Content on success.

Test Webhook Delivery

Send a sample webhook payload to a target URL to verify your endpoint is configured correctly. This is useful for verifying your webhook endpoint is working before creating a subscription.

Request Body

Example Request

Response

Test webhook payloads include the header X-Webhook-Test: true so your endpoint can distinguish test deliveries from real ones. If you have an active subscription for target_url and event_type, the test request is also signed with that subscription’s webhook_secret in the X-Webhook-Signature header, exactly like a real delivery. The X-Webhook-Test header is not covered by the signature, so check it before processing a delivery.