---
title: "Create webhook"
method: POST
path: "/webhooks"
tags: ["Webhooks"]
---

# Create webhook

`POST /webhooks`

Create a new webhook endpoint. The signing secret is returned only once.

## Headers

- `Idempotency-Key` string, required
- `X-Agent-ID` string, nullable
- `X-Instance-ID` string, nullable

## Request body

- object
  - `data` object, required
    - `attributes` object, required
      - `url` string, uri, required — Webhook endpoint URL
      - `description` string — Human-readable description
      - `enabledEvents` string[], required — Event types to subscribe to
      - `tags` object — Custom metadata tags (max 30 keys; keys 1-128 characters, alphanumeric and underscores; values 1-256 characters). Visible to any party authorized to read the resource; do not store sensitive data.

## Response `201`

Successful Response

- object
  - `data` object, required
    - `type` 'webhook', required — Resource type
    - `id` string, required — Resource ID (whk_xxx)
    - `attributes` object, required — Resource attributes
      - `url` string, uri, required — Webhook endpoint URL
      - `description` string, required — Human-readable description
      - `status` 'ENABLED' | 'DISABLED', required — Webhook status
      - `enabledEvents` string[], required — Event types this webhook listens to
      - `tags` object, required — Custom metadata tags. Visible to any party authorized to read the resource.
      - `createdAt` string, date-time, required — Creation timestamp (ISO 8601)
      - `updatedAt` string, date-time, required — Last update timestamp (ISO 8601)
      - `signingSecret` string, required — Webhook signing secret (shown only once — store securely!)
    - `relationships` object, required — Resource relationships
      - `party` object, required — Party that owns the webhook
        - `data` object, required — Related resource identifier
          - `type` 'party', required — Resource type
          - `id` string, required

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found — returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

---

[API](https://skmtc.dev/natural/apis/natural-api.md) · [All operations](https://skmtc.dev/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/natural/natural-api/revisions/8cc2aed45847/schema)
