Skip to content

Create a webhook subscription

View as Markdown
post /api/webhook_subscriptions

Creates a WebhookSubscription resource.

Subscribes a callbackUrl (an HTTPS endpoint) to a webhook topic. topic, callbackUrl and version are required: pin the version of the delivered payload (such as 2026-07) so its shape never changes without you asking. Optionally narrow the payload with includeFields. Requires the webhooks:write and webhooks:read scopes.

Request body

PropertyTypeRequiredDescription
callbackUrlstring | nullrequired
includeFieldsarray | null-Dot-path field selection limiting the delivered payload. Null or empty means the full payload. A * segment is a wildcard (e.g. *.id); the resource id is always included.
topic"product/created" | "product/updated" | "product/deleted"required
versionstring | nullrequiredThe API version of the delivered payload (e.g. 2026-07 or unstable). Required: pin it explicitly so the shape you receive never changes without you asking.

Response

201 - WebhookSubscription resource created

PropertyTypeRequiredDescription
@contextstring | object-
@idstringrequired
@typestringrequired
callbackUrlstring | null-The HTTPS endpoint notified when the topic fires.
createdAtstring-
idstring-
includeFieldsarray | null-Dot-path field selection limiting the delivered payload. Null or empty means the full payload. A * segment is a wildcard (e.g. *.id); the resource id is always included.
secretstring | null-The signing secret. Returned only once, in the creation response.
topicstring | null-The event topic to subscribe to.
updatedAtstring-
versionstring | null-The pinned payload API version, or null when dynamic.

Errors

400 - Invalid input

PropertyTypeRequiredDescription
@contextstring | object-
@idstringrequired
@typestringrequired
codestring-Stable identifier of the error in the error code catalogue (see /api/error-codes). Present on catalogued errors only.
descriptionstring | null-
detailstring | null-A human-readable explanation specific to this occurrence of the problem.
instancestring | null-A URI reference that identifies the specific occurrence of the problem. It may or may not yield further information if dereferenced.
messagestring-End-user message localized in the request locale, with this occurrence's values substituted. Present on catalogued errors only.
slugstring-Stable, readable key of the error in the error code catalogue. Present on catalogued errors only.
statusinteger | null-
titlestring | null-A short, human-readable summary of the problem. For a catalogued error it repeats the slug.
typestring-A URI reference that identifies the problem type. For a catalogued error it is the error code resource, /api/error-codes/{code}.

403 - Access denied. The caller is missing one or more permissions required for this operation.

Content-Type: application/problem+json

PropertyTypeRequiredDescription
@contextstring | object-
@idstringrequired
@typestringrequired
detailstring-
missingPermissionsstring[]-Permissions that the caller is missing for this operation. Present only when the 403 is caused by a denied permission.
statusinteger-
titlestring-
typestring-

422 - An error occurred

PropertyTypeRequiredDescription
@contextstring | object-
@idstringrequired
@typestringrequired
descriptionstring-
detailstring-
instancestring | null-
statusinteger-
titlestring | null-
typestring-
violationsobject[]-
Show violations fields
PropertyTypeRequiredDescription
codestring-The code of the violation
hintstring-An extra hint to understand the violation
messagestringrequiredThe message associated with the violation
parametersobject-Dynamic placeholder values for the violation message template (substitute into the code catalogue message).
payloadobject-The serialized payload of the violation
propertyPathstringrequiredThe property path of the violation
slugstring-Stable centralized error-code slug for this violation (see /api/error-codes).