/v1/webhooks/endpointsstableCreate an endpoint
- Needs
- Manage webhook endpoints
(webhooks:write) - Plan
- Any plan with API access
- Limits
- 60 a minute per key
- Dry run
- Yes — every check runs with ?dry_run=true, nothing changes
- Undo
- Delete the endpoint.
Starts sending the chosen events to your URL. The response contains the signing secret, shown only this once — store it; you need it to check signatures. Lost it? Rotate it.
Try it
Protects against doing it twice if you retry: a retry with the same key gets the first answer back instead of running again.
Code and response
curl -X POST 'https://mcp.wa-api.cloud/v1/webhooks/endpoints?dry_run=true' \
-H "Authorization: Bearer $API_KEY" \
-H 'Content-Type: application/json' \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"url": "https://hooks.example.com/incoming",
"event_type_ids": [
"contact.created/1",
"conversation.closed/1"
],
"description": "Order system"
}'The code reads your key from $API_KEY.
Body
| Field | Type | What it is |
|---|---|---|
| urlrequired | string | A public https URL. Private and local addresses are refused.1–2048 characters |
| event_type_idsrequired | array of string | Event type ids with version, e.g. contact.created/1.1–200 itemsSigned in? Pick one from your data with “My data”. |
| description | string | A note for your team.0–500 characters |
| custom_headers | object | Extra headers sent with every delivery, e.g. your own auth header. Replaces the whole set; {} removes all. Names starting Webhook- or Wc-, and Content-, Host, User-Agent, Idempotency-Key and Proxy- are reserved. |
| payload_format | string | envelope (recommended): the wrapped body with id, type, version, api_version, occurred_at and data. data: only the event data, the older format. Default for endpoints made with this API: envelope.one of: data, envelope · default "envelope" |
Headers
| Field | Type | What it is |
|---|---|---|
| Authorizationrequired | header | Bearer $API_KEY — your API key. |
| Api-Version | header | The API version to use, e.g. 2026-10-01. Default: the version your key is pinned to.one of: 2026-10-01 · pattern ^\d{4}-\d{2}-\d{2}$ |
| Idempotency-Keyrequired | header | Required here. Any unique string (8–128 characters), e.g. your order id plus the step. Kept 24 hours. Not needed with dry_run=true.pattern ^[A-Za-z0-9._:-]+$ · 8–128 characters |
Response 201
The endpoint and its signing secret (once).
| Field | Type | What it is |
|---|---|---|
| endpointrequired | object | |
| idrequired | string | |
| urlrequired | string | |
| descriptionrequired | string or null | |
| statusrequired | string | active | disabled | paused |
| custom_headersrequired | object | Custom header names; values masked to the last 4 characters. |
| consecutive_failuresrequired | number | |
| disabled_atrequired | string or null | |
| disabled_reasonrequired | string or null | |
| signing_secretrequired | string | Always masked. The secret is shown once, on create or rotate. |
| payload_formatrequired | string | "data" = the event's data object as the body; "envelope" = {id, type, version, api_version, occurred_at, company_id, data}.one of: data, envelope |
| created_atrequired | string or null | |
| updated_atrequired | string or null | |
| subscriptions | object or null | |
| countrequired | number | |
| all_activerequired | boolean | |
| event_typesrequired | array of object | |
| signing_secretrequired | string | |
| warningrequired | string | |
| dry_run | boolean | true when this was a dry run: every check ran and nothing changed. |
Errors
Errors are application/problem+json. Branch on code.
| Status | Code | When |
|---|---|---|
| 400 | invalid_input | A field is missing or has the wrong format. |
| 401 | unauthenticated | The Authorization header is missing, the key is unknown, expired or revoked. |
| 403 | entitlement_required | The workspace's plan does not include API access ( |
| 403 | insufficient_scope | The key does not have the permission this operation needs. |
| 409 | conflict | Also returned while a request with the same Idempotency-Key is still running. |
| 429 | rate_limited | The key or workspace went over its rate limit. Wait for |
| 503 | upstream_unavailable | A service behind the API is briefly unavailable. Safe to retry with backoff. |
| 504 | timeout | The change did not finish in time. Retry with the same Idempotency-Key: it never runs twice. |
Examples
Receive new contacts and closed conversations
Request body
{
"url": "https://hooks.example.com/incoming",
"event_type_ids": [
"contact.created/1",
"conversation.closed/1"
],
"description": "Order system"
}Response 201
{
"endpoint": {
"id": "ep_01J8Z6Q4M9W2X7K3B5N1R0T8YA",
"url": "https://hooks.example.com/incoming",
"description": "Order system",
"status": "active",
"custom_headers": {
"X-Hook-Token": "••••9f2a"
},
"payload_format": "envelope",
"consecutive_failures": 0,
"disabled_reason": null,
"signing_secret": "whsec_••••••••",
"created_at": "2026-09-10T12:00:00Z",
"updated_at": "2026-09-10T12:00:00Z",
"disabled_at": null
},
"signing_secret": "whsec_EXAMPLE_not_a_real_secret_000000000000",
"warning": "Store this secret now. It will not be shown again."
}Operation path
The same operation is also at POST /v1/ops/webhooks_create_endpoint, with every field in the JSON body.