Create Webhook Subscription
POST/api/webhook-subscriptions
Create a subscription. Body fields:
webhooks:manageGrant this scope to your token under Settings → Developer → Personal Access Tokens.
event(required, string) — wire event name; must be one of the catalog events (see List Events). The token must also hold that event's READ scope.target_url(required, string, max 2048, valid URL) — HTTPS endpoint to receive deliveries. Must pass the SSRF guard (public host only).
The signing secret is returned in the response exactly once and is never retrievable again — store it immediately.
Idempotent on (event, target_url): a duplicate POST returns the existing subscription with HTTP 200 (and no secret) instead of creating a new one (HTTP 201).
Request
Responses
- 200
- 201
- 401
- 403
- 422
- 429
OK
Response Headers
Created
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Unprocessable Entity
Response Headers
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.