Skip to content

Register a webhook trigger

POST
/v1/webhooks
curl --request POST \
--url https://example.com/v1/webhooks \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "flowId": "example", "flowVersion": "example", "config": { "input": "example" }, "hmacSecretName": "example", "label": "example" }'

Registers a kind=webhook trigger. The route mints webhookId (a random UUID). Caller must have written the plaintext HMAC secret to /v1/secrets first and passes the resulting name as hmacSecretName — the trigger never stores the plaintext. Rotation flows through POST /v1/secrets/:name/rotate.

Idempotency-Key
string
>= 1 characters

Caller-supplied idempotency key. Retries with the same key return the original response byte-identical (per docs/API-ROUTE-CONVENTIONS.md §3.1).

Media typeapplication/json
object
flowId
required
string
>= 1 characters
flowVersion
required
string
>= 1 characters
config
object
input
hmacSecretName
required

Handle into the tenant secrets store. Caller writes plaintext to /v1/secrets first and passes the name here.

string
>= 1 characters
label
string
Examplegenerated
{
"flowId": "example",
"flowVersion": "example",
"config": {
"input": "example"
},
"hmacSecretName": "example",
"label": "example"
}

Webhook registered.

Media typeapplication/json
object
triggerId
required
string
webhookId
required

Routable identifier used in the external receiver URL. Route-minted; unique per tenant.

string
flowId
required
string
>= 1 characters
flowVersion
required
string
>= 1 characters
input

Override input; absent → the parsed request body is passed to the flow.

hmacSecretName
required

Handle into the tenant secrets store. Plaintext HMAC secrets never touch this row — the caller writes plaintext to /v1/secrets first, then passes the name here.

string
>= 1 characters
label
required
string | null
status
required

Lifecycle status. Only active triggers fire. Tombstoned rows are excluded from every read path.

string
Allowed values: active paused
lastFiredAt
required
string | null format: date-time
createdAt
required
string format: date-time
updatedAt
required
string format: date-time
Example
{
"status": "active"
}

Malformed request body.

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}

Missing / malformed / expired / revoked bearer token.

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}

Route-minted webhookId collided (astronomically rare).

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}

Server error (unmapped domain code or framework crash).

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}