---
title: "Update Superagent webhook"
method: PATCH
path: "/api/agents/{agent_id}/webhooks/{webhook_id}"
---

# Update Superagent webhook

`PATCH /api/agents/{agent_id}/webhooks/{webhook_id}`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Changes a Superagent's webhook.

Send only the fields you want to change. Send `description: null` to remove the label. `events` takes one or more of `message.created`, which fires when a message is added to a conversation, and `message.completed`, which fires when the agent finishes a reply. `target_url` has to be a public HTTPS URL.

`enabled: true` turns a webhook back on after Base44 turned it off for failing, and resets `consecutive_failures`. `enabled: false` turns it off. `signing: "rotate"` generates a new signing secret and returns it once in `secret`, and `signing: "disable"` stops signing deliveries.

<Note>This endpoint accepts a personal API key or personal access token belonging to an editor of the agent. A read-only key is refused, and workspace API keys are not accepted.</Note>

## Path parameters

- `webhook_id` string, required — ID of the webhook to change. Get it from [List Superagent webhooks](/api-reference/list-superagent-webhooks).
- `agent_id` string, required — ID of the Superagent. It's the agent's app ID, shown in the agent's developer settings.

## Request body

- UpdateWebhookPayload
  - `target_url` string, nullable — New public HTTPS URL that receives the events.
  - `events` string[], nullable — New set of events to receive. One or more of `message.created` and `message.completed`.
  - `description` string, nullable — New label for the webhook, or `null` to remove it.
  - `enabled` boolean, nullable — `true` turns the webhook back on and resets `consecutive_failures`. `false` turns it off.
  - `signing` string, nullable — `rotate` generates a new signing secret and returns it once in `secret`. `disable` removes the secret, so deliveries are no longer signed.

## Response `200`

The updated webhook.

- SuperagentWebhookWithSecret — A webhook subscription, with its signing secret when one was just generated.
  - `id` string, required — ID of the webhook.
  - `target_url` string, required — HTTPS URL Base44 sends the events to.
  - `events` string[], required — Events the webhook receives. `message.created` fires when a message is added to a conversation, and `message.completed` when the agent finishes a reply.
  - `description` string, nullable, required — Your label for the webhook, or `null` when it has none.
  - `has_secret` boolean, required — Whether deliveries are signed. When `true`, each delivery carries an `X-Base44-Signature` header, an HMAC-SHA256 of the body.
  - `last_trigger_time` string, date-time, nullable, required — Time of the last delivery attempt, successful or not, as a UTC timestamp in ISO 8601 format, or `null` before the first one.
  - `last_error` SuperagentWebhookError, required
    - `message` string, required — What went wrong on the last delivery.
    - `attempted_at` string, date-time, required — Time of the failed delivery, as a UTC timestamp in ISO 8601 format.
    - `status_code` integer, nullable — HTTP status your endpoint answered with, when it answered with a non-2xx status.
    - `response_body` string, nullable — Start of your endpoint's response body, up to 512 bytes, when it answered with a non-2xx status.
    - `error_type` string, nullable — Kind of failure when the request didn't get an answer, such as a timeout or a refused connection.
  - `consecutive_failures` integer, required — Deliveries that failed in a row. After 20, Base44 turns the webhook off and sets `disabled_at`.
  - `disabled_at` string, date-time, nullable, required — Time the webhook was turned off, as a UTC timestamp in ISO 8601 format, or `null` while it's on. Turn it back on with `enabled: true` in [Update Superagent webhook](/api-reference/update-superagent-webhook).
  - `created_date` string, date-time, required — Time the webhook was created, as a UTC timestamp in ISO 8601 format.
  - `updated_date` string, date-time, required — Time the webhook last changed, as a UTC timestamp in ISO 8601 format.
  - `secret` string, nullable — The signing secret, returned only in the response that generates it. Store it, because no other response shows it again.

## Other responses

- `400` — `agent_id` belongs to an app that isn't a Superagent.
- `401` — Missing or invalid credentials.
- `402` — Agent webhooks need the Builder plan or higher.
- `403` — You aren't an editor of this agent, you're a viewer in its workspace, your API key is read-only, or you used a workspace API key.
- `404` — Agent or webhook not found.
- `422` — Validation Error
- `429` — Rate limit exceeded (100 requests per minute).

## Changes

- **2026-10-04** `4babe63df3b7` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/idealspot/apis/base44-app-management-api/changes/api/agents/:agent_id/webhooks/:webhook_id/patch.md)

---

[API](https://skmtc.dev/idealspot/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/idealspot/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/idealspot/apis/base44-app-management-api/revisions/76f124abd92c?raw)
