Skip to main content
Adds a webhook endpoint. Every delivery to it is signed with its secret (the X-FireFlo-Signature header), and the answer is the only time the secret is shown: keep it. A lost secret is replaced with rotate-secret.
Needs the webhooks:write scope.

Body

Send an Idempotency-Key header to make a retry safe: the same key with the same body is answered once, and the first answer repeated (with Idempotent-Replayed: true).

Request

Response

201 Created — the endpoint, with secret. events comes back sorted, without repeats.

Errors

Every refusal is {"error": {"code", "message", "field"}}; field is there when one input is at fault. Any request can also be refused for its key, its account or its rate (key_required, invalid_key, account_suspended, plan_excludes_api, address_not_allowed, rate_limited); see the overview.