Skip to main content
POST
Create a webhook endpoint

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

Idempotency-Key
string
required

Required. At most 255 characters of valid UTF-8 with no NUL byte; a missing key is refused with 400 idempotency_key_required and a malformed one with 400 invalid_idempotency_key. A retry with the same key and body returns the original successful response for 24 hours; a request that failed can be sent again under the same key. The same key with a different body is refused with 409 idempotency_key_conflict, and while the first request is still running with 409 idempotency_key_in_progress and a Retry-After header.

Required string length: 1 - 255

Body

application/json
event_types
string[]
required

Each type must be one GET /v1/webhooks/event-types lists with accepts_new_subscriptions true (absent means true). One listed with false is refused with 422 validation_failed and an event_types error reading No longer offered for new subscriptions: <types>; one not listed is refused the same way as Unknown event type: <types>. A list naming both kinds gets both errors in one response.

Minimum array length: 1
notification_email
string<email>
required

Where COPE sends the notice when it disables this endpoint automatically. An update through this API replaces it; the COPE dashboard sets it when it creates an endpoint and does not change it.

url
string<uri>
required
Maximum string length: 2048
Pattern: ^https://
Example:

"https://checkout.example.com/cope/webhooks"

active
boolean
description
string | null
Maximum string length: 500

Response

Created webhook endpoint with one-time signing secret. A retry with the same Idempotency-Key returns the same body minus signing_secret (WebhookEndpointSecretReplayResponse): the stored idempotent response holds no copy of the secret. If the first response was lost, rotate the secret under a new Idempotency-Key.

data
object
required