Add a provider signing/verification secret to an endpoint
curl --request POST \
--url https://api.webhook.co/v1/endpoints/{endpointId}/provider-secrets \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"secret": "<string>",
"label": "<string>",
"kind": "signing_secret"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({secret: '<string>', label: '<string>', kind: 'signing_secret'})
};
fetch('https://api.webhook.co/v1/endpoints/{endpointId}/provider-secrets', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.webhook.co/v1/endpoints/{endpointId}/provider-secrets"
payload = {
"secret": "<string>",
"label": "<string>",
"kind": "signing_secret"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.webhook.co/v1/endpoints/{endpointId}/provider-secrets"
payload := strings.NewReader("{\n \"secret\": \"<string>\",\n \"label\": \"<string>\",\n \"kind\": \"signing_secret\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"provider": "stripe",
"status": "active"
}{
"error": "<string>",
"message": "<string>"
}{
"error": "<string>",
"message": "<string>"
}{
"error": "<string>",
"message": "<string>"
}<string>Endpoints
Add a provider signing/verification secret to an endpoint
POST
/
v1
/
endpoints
/
{endpointId}
/
provider-secrets
Add a provider signing/verification secret to an endpoint
curl --request POST \
--url https://api.webhook.co/v1/endpoints/{endpointId}/provider-secrets \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"secret": "<string>",
"label": "<string>",
"kind": "signing_secret"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({secret: '<string>', label: '<string>', kind: 'signing_secret'})
};
fetch('https://api.webhook.co/v1/endpoints/{endpointId}/provider-secrets', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.webhook.co/v1/endpoints/{endpointId}/provider-secrets"
payload = {
"secret": "<string>",
"label": "<string>",
"kind": "signing_secret"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.webhook.co/v1/endpoints/{endpointId}/provider-secrets"
payload := strings.NewReader("{\n \"secret\": \"<string>\",\n \"label\": \"<string>\",\n \"kind\": \"signing_secret\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"provider": "stripe",
"status": "active"
}{
"error": "<string>",
"message": "<string>"
}{
"error": "<string>",
"message": "<string>"
}{
"error": "<string>",
"message": "<string>"
}<string>Authorizations
A whk_-prefixed API key (opaque; not a JWT).
Path Parameters
Pattern:
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Body
application/json
The server additionally validates the secret shape per provider (e.g. a Standard-Webhooks secret must be base64 key material); a malformed value is rejected with 400 VALIDATION_ERROR.
Available options:
stripe, github, shopify, slack, standard_webhooks, clerk, resend, stytch, supabase, render, brex, openai, replicate, polar, gemini, incident_io, etsy, vanta, pusher, quickbooks, chargify, launchdarkly, modern_treasury, autodesk_aps, mongodb_atlas, xero, segment, aftership, onfleet, webflow, klaviyo, mux, shippo, buildkite, ms_teams, ably, squarespace, nylas, linkedin, tiktok, airship, lob, persona, bolt, primer, airwallex, affirm, keygen, constant_contact, telegram, mixpanel, new_relic, fillout, zapier, tally, loops, customer_io, framer, box, configcat, ashby, merge_dev, cronofy, increase, finch, knock, deel, razorpay, sentry, linear, dropbox, checkout_com, lemon_squeezy, coinbase_commerce, dwolla, gocardless, notion, meta, woocommerce, bitbucket, atlassian_jira, x, clickup, npm, heroku, dub, cal_com, asana, circleci, pagerduty, airtable, calendly, zoom, sinch, workos, front, zendesk, twitch, paddle, recurly, docusign, vercel, intercom, paystack, authorize_net, sanity, square, trello, twilio, mandrill, hubspot, adyen, mailgun, mercado_pago, braintree, contentful, plivo, typeform, messagebird, netlify, vonage, monday, jira_connect, discord, telnyx, sendgrid, wise, kinde, paypal, aws_sns, plaid, ebay, gitlab, microsoft_graph, chargebee, postmark, sparkpost, okta, bigcommerce, datadog, brevo, checkr, doppler, sendbird Required string length:
1 - 4096Required string length:
1 - 200Available options:
signing_secret, verify_token, braintree_public_key Response
Success.
Pattern:
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Available options:
stripe, github, shopify, slack, standard_webhooks, clerk, resend, stytch, supabase, render, brex, openai, replicate, polar, gemini, incident_io, etsy, vanta, pusher, quickbooks, chargify, launchdarkly, modern_treasury, autodesk_aps, mongodb_atlas, xero, segment, aftership, onfleet, webflow, klaviyo, mux, shippo, buildkite, ms_teams, ably, squarespace, nylas, linkedin, tiktok, airship, lob, persona, bolt, primer, airwallex, affirm, keygen, constant_contact, telegram, mixpanel, new_relic, fillout, zapier, tally, loops, customer_io, framer, box, configcat, ashby, merge_dev, cronofy, increase, finch, knock, deel, razorpay, sentry, linear, dropbox, checkout_com, lemon_squeezy, coinbase_commerce, dwolla, gocardless, notion, meta, woocommerce, bitbucket, atlassian_jira, x, clickup, npm, heroku, dub, cal_com, asana, circleci, pagerduty, airtable, calendly, zoom, sinch, workos, front, zendesk, twitch, paddle, recurly, docusign, vercel, intercom, paystack, authorize_net, sanity, square, trello, twilio, mandrill, hubspot, adyen, mailgun, mercado_pago, braintree, contentful, plivo, typeform, messagebird, netlify, vonage, monday, jira_connect, discord, telnyx, sendgrid, wise, kinde, paypal, aws_sns, plaid, ebay, gitlab, microsoft_graph, chargebee, postmark, sparkpost, okta, bigcommerce, datadog, brevo, checkr, doppler, sendbird Available options:
active, retiring, revoked Was this page helpful?