Skip to main content
Webhooks

Update a Webhook Endpoint

Update an Endpoint receiver URL, description, subscribed events, or metadata.

Webhook is currently in Beta. APIs, fields, and behavior may change in future versions.
PUT /api/v1/forward/webhook/endpoints/{endpoint_id} Only fields included in the request are updated. Omitted fields keep their current values.

Headers

HeaderRequiredDescription
AuthorizationYesBearer <PAT or administrator SAT>
Content-TypeYesapplication/json

Path parameters

ParameterTypeRequiredDescription
endpoint_idstringYesWebhook Endpoint ID.

Body parameters

FieldTypeRequiredDescription
urlstringNoNew event receiver URL. HTTPS is recommended in production.
descriptionstringNoNew purpose description.
eventsstring[]NoReplaces the complete subscription list. Must contain at least one item. Accepts * or specific event names; prefix wildcards are not supported. See Supported public events for full event names and triggers.
activebooleanNoWhether the Endpoint is enabled. You can also use the dedicated enable or disable API.
metadataobjectNoMerges custom metadata. Values are strings; pass null to remove a key.

Example request

curl -s -X PUT 'https://api.qoder.com/api/v1/forward/webhook/endpoints/e149c233-1234-4abc-8def-1234567890ab' \
  -H "Authorization: Bearer $QODER_PAT" \
  -H 'Content-Type: application/json' \
  -d '{
    "description": "Schedule completion notifications",
    "events": [
      "forward.schedule_run.succeeded",
      "forward.schedule_run.failed"
    ]
  }'

Example response

HTTP 200 OK
{
  "id": "e149c233-1234-4abc-8def-1234567890ab",
  "url": "https://example.com/webhooks/qoder",
  "description": "Schedule notifications",
  "events": [
    "forward.schedule.created",
    "forward.schedule_run.succeeded",
    "forward.schedule_run.failed"
  ],
  "metadata": {
    "environment": "production"
  },
  "active": true,
  "last_success_at": "2026-09-01T09:07:59Z",
  "last_failure_at": null,
  "consecutive_fail": 0,
  "created_at": "2026-09-01T08:00:00Z",
  "updated_at": "2026-09-01T09:07:59Z"
}
See Get a Webhook Endpoint for response fields. Updating an Endpoint does not return or rotate signing_secret.

Errors

HTTPTypeTrigger
400invalid_request_errorThe URL, event list, metadata, or request body is invalid.
401authentication_errorAuthentication is missing, invalid, or expired.
403permission_errorThe current token cannot manage Webhooks.
404not_found_errorThe Endpoint does not exist or is not visible to the current account.
413invalid_request_errorThe request body is too large.
500/502/503api_errorThe service is temporarily unavailable.