Bulk Delete Webhook Events
DELETE/api/xero/webhook-settings/:integrationInstanceId/events
Permanently delete webhook events in bulk. This only removes the stored event records (the audit feed); it does not undo any data changes the events triggered. Requires an explicit confirmation value of YES.
Any valid API token can call this endpoint — no specific scope required. Manage tokens.
Body (one of two selection modes):
event_ids(array of integers, required unlessapply_to_allis true): explicit event IDs to delete. Each ID must exist.apply_to_all(boolean, optional): when true, delete every event matchingfiltersinstead of an explicit ID list.filters(object, optional, used withapply_to_all): flat filter map using the same keys as List Webhook Events'filter[...]parameters, e.g.{"status": "duplicate"}.confirmation(string, required): must be exactlyYES.
Returns the number of rows removed.
Authentication: Bearer token.
Request
Responses
- 200
- 401
- 403
- 404
- 422
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Unprocessable Entity
Response Headers
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.