Skip to main content
A webhook endpoint is a URL in your app. The engine sends it a POST with a JSON body whenever one of the events you chose happens.

Create an endpoint

string
required
Your HTTPS endpoint.
string[]
required
The events sent to this URL. At least one. See Events for the full list.
string[]
Only events of these accounts (acc_…). Empty means every account.
string
Your description. It isn’t sent in events.
object[]
Extra headers sent with every call, as { "key", "value" }.
boolean
default:"true"
false creates it paused.
Response
secret signs every call to this endpoint. Store it and use it to verify signatures. It’s also returned when you get or list the endpoint.
Treat secret like a password. Anyone who has it can forge calls that pass your signature check.

Manage endpoints

Change an endpoint

Response
  • Fields you don’t send keep their value. headers, trigger_events and account_ids replace the whole list.
  • Send "enabled": false to pause it, and "enabled": true to resume. Calls waiting while it’s paused are dropped.
Endpoints can also be managed in your dashboard under Webhooks.

Delivery log

Every call to an endpoint is a conversation (whc_…). List them to see what was sent and what your endpoint answered:
string
required
The endpoint (we_…).
string
Only the calls of this event (evt_…).
integer
default:"50"
1 to 250.
integer
default:"0"
How many calls to skip.
Response
Your dashboard shows the same log under Webhooks.

Your endpoint

  • Answer with any 2xx status, quickly (within 10 seconds). Do the slow work afterwards, for example in a queue.
  • Anything else, or no answer, is retried.
  • An event can arrive more than once. Use the event id (evt_…) to skip duplicates.
  • Events can arrive out of order. When order matters, fetch the email again to get its current state.
  • URLs that resolve to private or local addresses (10.x, 192.168.x, localhost) are refused, and redirects aren’t followed.