Update webhook endpoint
Update a webhook endpoint's URL, subscribed events, description, or enabled status. --- **Related endpoints** - `GET /webhook-endpoints` — List webhook endpoints - `POST /webhook-endpoints` — Create webhook endpoint - `GET /webhook-endpoints/{id}` — Get webhook endpoint - `DELETE /webhook-endpoints/{id}` — Delete webhook endpoint - `POST /webhook-endpoints/{id}/rotate-secret` — Rotate signing secret **Common errors** - `400 invalid_request` — malformed payload or failed validation. - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key. **Idempotency** Pass an `Idempotency-Key` header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see [the idempotency guide](/docs/fundamentals/idempotency).
Update a webhook endpoint's URL, subscribed events, description, or enabled status.
Related endpoints
GET /webhook-endpoints— List webhook endpointsPOST /webhook-endpoints— Create webhook endpointGET /webhook-endpoints/{id}— Get webhook endpointDELETE /webhook-endpoints/{id}— Delete webhook endpointPOST /webhook-endpoints/{id}/rotate-secret— Rotate signing secret
Common errors
400 invalid_request— malformed payload or failed validation.401 authentication_error— missing, invalid, expired, or revoked credential. Codes:authentication_failed,invalid_api_key,expired_api_key,api_key_revoked,session_invalid,merchant_required. Carries aWWW-Authenticate: Bearerchallenge.404 resource_missing— the referenced resource does not exist or is not visible to your key.
Idempotency
Pass an Idempotency-Key header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see the idempotency guide.
Your RevKeen merchant API key. Create and manage keys in Dashboard → Settings → Developer. Use rk_sandbox_* for staging/test and rk_live_* for production. The same key may be sent as Authorization: Bearer <key> if that suits your HTTP client better. A missing, invalid, expired, or revoked key returns 401 with a WWW-Authenticate: Bearer challenge; a valid key without the required scope returns 403.
In: header
Path Parameters
Webhook endpoint ID
uuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X PATCH "https://api.revkeen.com/v2/webhook-endpoints/00000000-0000-0000-0000-000000000000" \
-H "x-api-key: $REVKEEN_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"url": "https://example.com",
"enabled_events": [
"string"
],
"description": null,
"enabled": false
}'{ "data": { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "url": "http://example.com", "description": "string", "enabled_events": [ "string" ], "status": "enabled", "circuit_breaker_state": "closed", "total_deliveries": 0, "successful_deliveries": 0, "failed_deliveries": 0, "last_delivery_at": "2019-08-24T14:15:22Z", "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z" }}Rotate signing secret POST
Generate a new signing secret for a webhook endpoint. The old secret is immediately invalidated. Store the new secret securely — it is only returned in this response. --- **Related endpoints** - `GET /webhook-endpoints` — List webhook endpoints - `POST /webhook-endpoints` — Create webhook endpoint - `GET /webhook-endpoints/{id}` — Get webhook endpoint - `PATCH /webhook-endpoints/{id}` — Update webhook endpoint - `DELETE /webhook-endpoints/{id}` — Delete webhook endpoint **Common errors** - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key. **Idempotency** Pass an `Idempotency-Key` header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see [the idempotency guide](/docs/fundamentals/idempotency).
Checkout session completed Webhook
Sent when a checkout session is successfully completed. **Action required:** Fulfill the customer's order.