---
title: "Create Superagent webhook"
method: POST
path: "/api/agents/{agent_id}/webhooks"
---

# Create Superagent webhook

`POST /api/agents/{agent_id}/webhooks`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Subscribes a URL to a Superagent's conversation events.

`events` takes one or more of `message.created`, which fires when a message is added to a conversation, and `message.completed`, which fires when the agent finishes a reply. `target_url` has to be a public HTTPS URL. An agent can have up to 5 webhooks, and each call adds one, so retrying a create that may have succeeded can add a duplicate. Check [List Superagent webhooks](/api-reference/list-superagent-webhooks) first.

Base44 sends each event once and doesn't retry a failed delivery. A failure is recorded in `last_error` and counts toward `consecutive_failures`.

Set `generate_secret` to `true` to sign deliveries. The response then carries `secret`, the only time Base44 shows it.

<Note>This endpoint accepts a personal API key or personal access token belonging to an editor of the agent. A read-only key is refused, and workspace API keys are not accepted.</Note>

## Path parameters

- `agent_id` string, required — ID of the Superagent. It's the agent's app ID, shown in the agent's developer settings.

## Request body

- CreateWebhookPayload
  - `target_url` string, required — Public HTTPS URL that receives the events.
  - `events` string[] — Events to receive. One or more of `message.created` and `message.completed`.
  - `description` string, nullable — Your label for the webhook.
  - `generate_secret` boolean — `true` makes Base44 generate an HMAC-SHA256 signing secret and return it once in the response. Deliveries are signed with an `X-Base44-Signature` header only when the webhook has a secret.

## Response `200`

The new webhook.

- SuperagentWebhookWithSecret — A webhook subscription, with its signing secret when one was just generated.
  - `id` string, required — ID of the webhook.
  - `target_url` string, required — HTTPS URL Base44 sends the events to.
  - `events` string[], required — Events the webhook receives. `message.created` fires when a message is added to a conversation, and `message.completed` when the agent finishes a reply.
  - `description` string, nullable, required — Your label for the webhook, or `null` when it has none.
  - `has_secret` boolean, required — Whether deliveries are signed. When `true`, each delivery carries an `X-Base44-Signature` header, an HMAC-SHA256 of the body.
  - `last_trigger_time` string, date-time, nullable, required — Time of the last delivery attempt, successful or not, as a UTC timestamp in ISO 8601 format, or `null` before the first one.
  - `last_error` SuperagentWebhookError, required
    - `message` string, required — What went wrong on the last delivery.
    - `attempted_at` string, date-time, required — Time of the failed delivery, as a UTC timestamp in ISO 8601 format.
    - `status_code` integer, nullable — HTTP status your endpoint answered with, when it answered with a non-2xx status.
    - `response_body` string, nullable — Start of your endpoint's response body, up to 512 bytes, when it answered with a non-2xx status.
    - `error_type` string, nullable — Kind of failure when the request didn't get an answer, such as a timeout or a refused connection.
  - `consecutive_failures` integer, required — Deliveries that failed in a row. After 20, Base44 turns the webhook off and sets `disabled_at`.
  - `disabled_at` string, date-time, nullable, required — Time the webhook was turned off, as a UTC timestamp in ISO 8601 format, or `null` while it's on. Turn it back on with `enabled: true` in [Update Superagent webhook](/api-reference/update-superagent-webhook).
  - `created_date` string, date-time, required — Time the webhook was created, as a UTC timestamp in ISO 8601 format.
  - `updated_date` string, date-time, required — Time the webhook last changed, as a UTC timestamp in ISO 8601 format.
  - `secret` string, nullable — The signing secret, returned only in the response that generates it. Store it, because no other response shows it again.

## Other responses

- `400` — `agent_id` belongs to an app that isn't a Superagent, or the agent already has 5 webhooks.
- `401` — Missing or invalid credentials.
- `402` — Agent webhooks need the Builder plan or higher.
- `403` — You aren't an editor of this agent, you're a viewer in its workspace, your API key is read-only, or you used a workspace API key.
- `404` — Agent not found.
- `422` — Validation Error
- `429` — Rate limit exceeded (100 requests per minute).

## Changes

- **2026-10-04** `4babe63df3b7` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/idealspot/apis/base44-app-management-api/changes/api/agents/:agent_id/webhooks/post.md)

---

[API](https://skmtc.dev/idealspot/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/idealspot/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/idealspot/apis/base44-app-management-api/revisions/76f124abd92c?raw)
