# Create webhooks

Register an endpoint to be notified on. Needs a name of up to 80 characters, an https URL of up to 2000 with no spaces, and at least one event from the closed list; `auth` says which credential the RECEIVER wants, and leaving it out means none. This is one of exactly two answers that ever carries the signing secret in full — keep it now, it cannot be read back. 409 on a duplicate name, 503 when this service holds no key to seal the secret with. Admin only.

Access class: `workspace:admin`.

## Endpoint

`POST /v1/webhooks`

## Request body

Content type: `application/json`.

```json
{
  "body": {
    "auth": {
      "credential": "string",
      "headerName": "string",
      "kind": "string"
    },
    "description": "string",
    "events": [
      "string"
    ],
    "name": "string",
    "url": "string"
  },
  "params": {},
  "query": {}
}
```

## Responses

### 201

the action's answer

Content type: `application/json`.

```json
{
  "data": {
    "secret": "string",
    "webhook": {
      "authHeaderName": "string",
      "authKind": "string",
      "createdAt": "string",
      "createdBy": 1,
      "description": "string",
      "events": [
        "string"
      ],
      "id": "",
      "name": "string",
      "secretHint": "string",
      "secretRotatedAt": "string",
      "status": "string",
      "updatedAt": "string",
      "url": "string"
    }
  }
}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
