Register a Webhook receiver URL and the events to subscribe to.
Webhook is currently in Beta. APIs, fields, and behavior may change in future versions.
POST /api/v1/forward/webhook/endpoints
Headers
| Header | Required | Description |
|---|---|---|
Authorization | Yes | Bearer <PAT or administrator SAT> |
Content-Type | Yes | application/json |
Idempotency-Key | No | Optional idempotency key. Reuse a key only for the same request. |
Body parameters
| Field | Type | Required | Description |
|---|---|---|---|
url | string | Yes | HTTP or HTTPS receiver URL. HTTPS is recommended in production. |
description | string | No | Purpose of the Endpoint. |
events | string[] | Yes | Event subscriptions. Must contain at least one item. Accepts * or a specific namespace.name event; prefix wildcards such as forward.* are not supported. See Supported public events for full event names and triggers. Only events in that catalog have a Forward delivery contract. |
metadata | object | No | Custom string key-value pairs. |
Example request
Example response
HTTP 201 Created
Response fields
| Field | Type | Description |
|---|---|---|
id | string | Endpoint ID. Store it as an opaque string. |
url | string | Event receiver URL. |
description | string | Endpoint description. |
events | string[] | Current event subscriptions. |
metadata | object | Custom metadata. The response may include fields maintained by the platform. |
active | boolean | Whether the Endpoint is enabled. New Endpoints are true. |
signing_secret | string | Secret used to verify Webhook signatures. Returned only in this response. |
created_at | string | Creation time, in RFC 3339 format. |
Securely store signing_secret immediately. List, get, and update APIs do not return it again.
Errors
| HTTP | Type | Trigger |
|---|---|---|
400 | invalid_request_error | The URL, event list, metadata, or request body is invalid. |
401 | authentication_error | Authentication is missing, invalid, or expired. |
403 | permission_error | The current token cannot manage Webhooks. |
409 | conflict_error | The idempotency key conflicts with an existing request, or the Endpoint limit has been reached. |
413 | invalid_request_error | The request body is too large. |
429 | rate_limit_error | The request rate limit has been reached. |

