Create webhook endpoint

Create a webhook endpoint to receive event notifications at the given URL. Returns the endpoint with its signing secret — store the secret securely, it is only shown once. --- **Related endpoints** - `GET /webhook-endpoints` — List webhook endpoints - `GET /webhook-endpoints/{id}` — Get webhook endpoint - `PATCH /webhook-endpoints/{id}` — Update webhook endpoint - `DELETE /webhook-endpoints/{id}` — Delete webhook endpoint - `POST /webhook-endpoints/{id}/rotate-secret` — Rotate signing secret **Common errors** - `400 invalid_request` — malformed payload or failed validation. - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `409 conflict` — Idempotency-Key collision with a different body, or a concurrent state-transition conflict. **Idempotency** Pass an `Idempotency-Key` header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see [the idempotency guide](/docs/fundamentals/idempotency).

POST
/webhook-endpoints

Create a webhook endpoint to receive event notifications at the given URL. Returns the endpoint with its signing secret — store the secret securely, it is only shown once.


Related endpoints

  • GET /webhook-endpoints — List webhook endpoints
  • GET /webhook-endpoints/{id} — Get webhook endpoint
  • PATCH /webhook-endpoints/{id} — Update webhook endpoint
  • DELETE /webhook-endpoints/{id} — Delete webhook endpoint
  • POST /webhook-endpoints/{id}/rotate-secret — Rotate signing secret

Common errors

  • 400 invalid_request — malformed payload or failed validation.
  • 401 authentication_error — missing, invalid, expired, or revoked credential. Codes: authentication_failed, invalid_api_key, expired_api_key, api_key_revoked, session_invalid, merchant_required. Carries a WWW-Authenticate: Bearer challenge.
  • 409 conflict — Idempotency-Key collision with a different body, or a concurrent state-transition conflict.

Idempotency

Pass an Idempotency-Key header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see the idempotency guide.

x-api-key<token>

Your RevKeen merchant API key. Create and manage keys in Dashboard → Settings → Developer. Use rk_sandbox_* for staging/test and rk_live_* for production. The same key may be sent as Authorization: Bearer <key> if that suits your HTTP client better. A missing, invalid, expired, or revoked key returns 401 with a WWW-Authenticate: Bearer challenge; a valid key without the required scope returns 403.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

Stuck on an error response? Ask the RevKeen assistant to explain it.
curl -X POST "https://api.revkeen.com/v2/webhook-endpoints" \
  -H "x-api-key: $REVKEEN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://example.com",
    "enabled_events": [
      "string"
    ]
  }'
{  "data": {    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",    "url": "http://example.com",    "description": "string",    "enabled_events": [      "string"    ],    "status": "enabled",    "secret": "string",    "circuit_breaker_state": "closed",    "total_deliveries": 0,    "successful_deliveries": 0,    "failed_deliveries": 0,    "last_delivery_at": "2019-08-24T14:15:22Z",    "created_at": "2019-08-24T14:15:22Z",    "updated_at": "2019-08-24T14:15:22Z"  }}

Retry a webhook delivery POST

Queue an immediate retry of this delivery. The delivery is marked `pending` and `next_retry_at` is set to now; the dispatcher picks it up on its next tick. Calling retry on an already-pending delivery just advances its retry time. Dead-lettered deliveries can be retried once; succeeded deliveries cannot. --- **Related endpoints** - `GET /webhook-deliveries` — List webhook deliveries - `GET /webhook-deliveries/{id}` — Retrieve a webhook delivery **Common errors** - `404 resource_missing` — the referenced resource does not exist or is not visible to your key. - `409 conflict` — Idempotency-Key collision with a different body, or a concurrent state-transition conflict. **Idempotency** Pass an `Idempotency-Key` header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see [the idempotency guide](/docs/fundamentals/idempotency).

Delete webhook endpoint DELETE

Permanently delete a webhook endpoint and all its event subscriptions. --- **Related endpoints** - `GET /webhook-endpoints` — List webhook endpoints - `POST /webhook-endpoints` — Create webhook endpoint - `GET /webhook-endpoints/{id}` — Get webhook endpoint - `PATCH /webhook-endpoints/{id}` — Update webhook endpoint - `POST /webhook-endpoints/{id}/rotate-secret` — Rotate signing secret **Common errors** - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key. **Idempotency** Pass an `Idempotency-Key` header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see [the idempotency guide](/docs/fundamentals/idempotency).