Skip to main content
POST
Rotate webhook secret

Authorizations

Authorization
string
header
required

Partner API Bearer key: Authorization: Bearer <key>. Keys are created only through authorized portal or staff flows.

Headers

Idempotency-Key
string
required

Required client-supplied command key scoped to the selected Case company or Partner owner, method, operation and path. An exact retry replays the original response while it is retained, including after credential rotation or replacement. Current permissions are required.

Maximum string length: 255

Path Parameters

id
string<uuid>
required

UUID of the webhook subscription in this request.

Response

Resource representation with a native UUID id.

auto_disabled
boolean
required
read-only

true when the endpoint was disabled automatically after reaching max_consecutive_failures; re-enable it with enabled: true once the destination is fixed.

consecutive_failures
integer
required
read-only

Consecutive terminal delivery failures counted against this endpoint. A successful delivery resets the counter to zero.

created_at
string<date-time>
required
read-only

Time at which the webhook subscription was created.

id
string<uuid>
required
read-only

Stable identifier for this resource.

last_failure_at
string<date-time> | null
required
read-only

Time of the latest counted terminal delivery failure since the last success; null before any failure or after a successful delivery.

updated_at
string<date-time>
required
read-only

Time at which the webhook subscription was last updated.

url
string<uri>
required

Publicly reachable HTTPS URL that receives webhook POST deliveries. The URL must be unique among this partner's v2 webhook endpoints.

Maximum string length: 2048
companies

Company selector for case and Mahnservice events: "*" includes every company with available partner case access, including companies added later; otherwise supply 1–500 accessible company UUIDs. Null makes the subscription lifecycle-only: no company case or Mahnservice events are delivered. Required for explicit case event types; omitted on PATCH preserves the selector.

Available options:
*
description
string

Optional single-line label for this webhook.

Maximum string length: 255
enabled
boolean

Whether deliveries are attempted. Re-enabling an endpoint resets its consecutive failure counter.

events
enum<string>[]

Event types this endpoint receives. Use ["*"] alone to subscribe to all event types, with case events delivered only when a companies selector is configured. Explicit case event types require companies.

  • * - *
  • company.created - company.created
  • company.case_submission_readiness.changed - company.case_submission_readiness.changed
  • company.access.confirmed - company.access.confirmed
  • company.access.revoked - company.access.revoked
  • company.access.restored - company.access.restored
  • company.user.added - company.user.added
  • company.user.revoked - company.user.revoked
  • company.user.activated - company.user.activated
  • company.user.invite_expired - company.user.invite_expired
  • order.submitted - order.submitted
  • order.withdrawn - order.withdrawn
  • order.rejected - order.rejected
  • order.accepted - order.accepted
  • order.expired - order.expired
  • mandate.created - mandate.created
  • mandate.state.changed - mandate.state.changed
  • mandate.status_update.published - mandate.status_update.published
  • mandate.balance_updated - mandate.balance_updated
  • order.message.created - order.message.created
  • mandate.message.created - mandate.message.created
  • request_to_client.created - request_to_client.created
  • request_to_client.answered - request_to_client.answered
  • payment.reported - payment.reported
  • statement.published - statement.published
  • statement.cancelled - statement.cancelled
  • single_mandate_statement.published - single_mandate_statement.published
  • single_mandate_statement.cancelled - single_mandate_statement.cancelled
  • invoice.created - invoice.created
  • invoice.paid - invoice.paid
  • invoice.cancelled - invoice.cancelled
  • invoice.written_off - invoice.written_off
  • dunning.level_advanced - dunning.level_advanced
  • dunning.handed_to_collection - dunning.handed_to_collection
Available options:
*,
company.created,
company.case_submission_readiness.changed,
company.access.confirmed,
company.access.revoked,
company.access.restored,
company.user.added,
company.user.revoked,
company.user.activated,
company.user.invite_expired,
order.submitted,
order.withdrawn,
order.rejected,
order.accepted,
order.expired,
mandate.created,
mandate.state.changed,
mandate.status_update.published,
mandate.balance_updated,
order.message.created,
mandate.message.created,
request_to_client.created,
request_to_client.answered,
payment.reported,
statement.published,
statement.cancelled,
single_mandate_statement.published,
single_mandate_statement.cancelled,
invoice.created,
invoice.paid,
invoice.cancelled,
invoice.written_off,
dunning.level_advanced,
dunning.handed_to_collection
max_consecutive_failures
integer

Automatically disables the endpoint when this many consecutive deliveries reach terminal failure. Retry attempts within one delivery do not each count.

Required range: 1 <= x <= 1000
secret_key
string
read-only

Signing secret shown once on creation or rotation. Store it to verify webhook signatures; list, retrieve, and idempotent replay responses omit it.