Update Webhook Settings
PATCH/api/xero/webhook-settings/:integrationInstanceId
Enable or disable Xero webhooks and update the signing key. Key rotation is supported with a 1-hour grace period for the previous key.
Any valid API token can call this endpoint — no specific scope required. Manage tokens.
Authentication: Requires Bearer token.
Fields:
- webhook_enabled (required, boolean): Enable or disable webhook processing
- signing_key (optional, string, min 32 max 256): HMAC-SHA256 signing key from Xero
Errors:
- 422: Cannot enable webhooks without a signing key
Request
Responses
- 200
- 401
- 403
- 404
- 422
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Unprocessable Entity
Response Headers
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.