Create a webhook configuration
Requires an owner/admin browser session with recent MFA. Tenant API keys and agent tokens cannot manage webhook configuration or delivery controls. Returns the webhook signing secret exactly once in the create response.
Headers
Unix seconds, Unix milliseconds, or HTTP/ISO timestamp. Sensitive mutating routes require this or X-Steward-Request-Expires-At when request-expiry or request signatures are enforced.
Unix seconds, Unix milliseconds, or HTTP/ISO expiry time. Sensitive mutating routes require this or X-Steward-Request-Timestamp when request-expiry or request signatures are enforced.
Authorization signature for sensitive mutating routes when STEWARD_REQUIRE_AUTH_SIGNATURE=true or production enforcement is enabled. Use v1=<hmac-sha256> or p256=<signature>.
Optional tenant request-signing key id used to select a managed HMAC signing key.
Required for signed sensitive requests and recommended for all sensitive mutating requests. Replays are scoped to authenticated or explicitly signed contexts.
Request body
Response
JSON response