---
title: "Update webhook"
method: PATCH
path: "/webhooks/{webhookId}"
tags: ["Webhooks"]
---

# Update webhook

`PATCH /webhooks/{webhookId}`

Update a webhook endpoint

## Path parameters

- `webhookId` string, required — Webhook ID (whk_*).

## Headers

- `Idempotency-Key` string, required
- `X-Instance-ID` string, nullable

## Request body

- object
  - `data` object, required
    - `attributes` object, required
      - `url` string, uri — New webhook endpoint URL.
      - `description` string — New description.
      - `status` 'ENABLED' | 'DISABLED' — New status.
      - `enabledEvents` string[] — Event types to subscribe to; use "*" to subscribe to all event types.
      - `sources` string[] — Event sources to receive: "own" for your own party's events, "connected" for events of parties connected to you through an active authorization.
      - `tags` object — Tag updates. Pass null to remove a key.

## Response `200`

Successful Response

- object
  - `data` object, required
    - `type` 'webhook', required
    - `id` string, required — Webhook ID (whk_*).
    - `attributes` object, required
      - `url` string, uri, required — Webhook endpoint URL.
      - `description` string, required — Webhook description.
      - `status` 'ENABLED' | 'DISABLED', required — Webhook status.
      - `enabledEvents` string[], required — Event types this webhook listens to.
      - `sources` string[], required — Event sources this webhook receives: "own" for your own party, "connected" for parties connected to you through an active authorization.
      - `tags` object, required — Metadata visible to anyone who can read the resource.
      - `createdAt` string, date-time, required — When this webhook was created.
      - `updatedAt` string, date-time, required — When this webhook was last updated.
    - `relationships` object, required
      - `party` object, required — Party that owns the webhook.
        - `data` object, required — Related resource identifier.
          - `type` 'party', required
          - `id` string, required

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found. Returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error. The response contains one error object for each invalid request value.
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

## Changes

- **2026-09-03** `5fe9af51616b` — 2 info
  - added the new optional request property `data/attributes/sources`
  - added the required property `data/attributes/sources` to the response with the `200` status
- **2026-09-02** `c7c12da5915f` — 12 info
  - added the optional property `errors/items/meta/limitScope` to the response with the `400` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `401` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `403` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `404` status
  - …8 more
- **2026-08-27** `359d267dca88` — 1 info
  - deleted the `header` request parameter `X-Agent-ID` with deprecation
- **2026-08-23** `b1ad79e918ac` — 1 info
  - `header` request parameter `X-Agent-ID` was deprecated
- **2026-08-19** `c2c65e052711` — 2 breaking, 2 info
  - removed the enum value `mandate.created` of the request property `data/attributes/enabledEvents/items/`
  - removed the enum value `mandate.revoked` of the request property `data/attributes/enabledEvents/items/`
  - removed the `mandate.created` enum value from the `data/attributes/enabledEvents/items/` response property for the response status `200`
  - removed the `mandate.revoked` enum value from the `data/attributes/enabledEvents/items/` response property for the response status `200`

[Full history](https://skmtc.dev/natural/apis/natural-api/changes/webhooks/:webhookId/patch.md)

---

[API](https://skmtc.dev/natural/apis/natural-api.md) · [All operations](https://skmtc.dev/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/natural/natural-api/revisions/440d168c49de/schema)
