Skip to main content
POST
Create a webhook endpoint

Authorizations

Authorization
string
header
required

API key: Authorization: Bearer sk_test_... or sk_live_....

Headers

Invoice-Version
string

Pin a dated API release (Stripe-style). Omit to use the current version. An unknown value returns 400 request.invalid_version. Echoed back on every response.

Example:

"2026-07-10"

Invoice-Account
string

Connect: act on behalf of one of your connected accounts (its acct_…/org_… id). Omit to act as your own organization. Not honored on /v1/api_keys.

Example:

"org_2P9connectedacct"

Idempotency-Key
string

Safely retry any POST. The first response is stored for 24h and replayed byte-for-byte for identical retries (the replay adds an idempotent-replayed: true header). Reusing the key with a different body is 409 idempotency.key_reuse; an in-flight duplicate is 409 idempotency.key_processing. This makes retrying a 502/429 safe — no duplicate stamp.

Example:

"a1b2c3d4-e5f6-4789-8abc-1234567890ab"

Body

application/json
url
string<uri>
required

HTTPS URL that receives event POSTs, e.g. "https://example.com/webhooks/invoice".

enabled_events
string[]

Event types to deliver: "" (all), a namespace wildcard like "invoice.", or exact types like "invoice.stamped". Default ["*"].

Minimum array length: 1
connect
boolean
default:false

Connect: when true (on a platform org), also receive events from ALL connected accounts. Each delivery's account field names which one. Default false.

metadata
object

Integrator-owned key-value map (≤50 keys), stored and echoed back verbatim.

Response

Default Response

object
enum<string>
required

Always "webhook_endpoint".

Available options:
webhook_endpoint
id
string
required

Webhook endpoint id, e.g. "we_2P9K3sample".

url
string
required

HTTPS URL events are delivered to.

enabled_events
string[]
required

Subscribed event types ("*", namespace wildcards, or exact types).

enabled
boolean
required

False when the endpoint is paused (disabled).

connect
boolean
required

True when this endpoint also receives connected-account events.

livemode
boolean
required

True if created with a live-mode key.

metadata
object
required

Integrator-owned key-value map echoed back.

created_at
string
required

Creation timestamp, ISO-8601 UTC.

updated_at
string
required

Last-update timestamp, ISO-8601 UTC.

secret
string
required

Signing secret ("whsec_…") for verifying delivery signatures — shown exactly once at creation.