> ## Documentation Index
> Fetch the complete documentation index at: https://omni.fireflo.au/llms.txt
> Use this file to discover all available pages before exploring further.

# POST /v1/webhooks

> Add a webhook endpoint; the answer carries its signing secret, shown this once.

Adds a webhook endpoint. Every delivery to it is signed with its secret (the `X-FireFlo-Signature` header), and the answer is the only time the secret is shown: keep it. A lost secret is replaced with [rotate-secret](/api-reference/webhooks/rotate-secret).

<Note>Needs the `webhooks:write` scope.</Note>

## Body

| Field | Type | Required | Notes |
| :- | :- | :- | :- |
| `url` | string | Yes | An `https://` address, up to 500 characters, reachable on the public internet. |
| `events` | array | Yes | Event names from [GET /v1/events](/api-reference/account/list-event-types), or `"*"` for every event. |
| `description` | string | No | A note, up to 200 characters. |
| `enabled` | boolean | No | False pauses it. Setting it true again clears `failing_since` and `disabled_reason`. |

Send an `Idempotency-Key` header to make a retry safe: the same key with the same body is answered once, and the first answer repeated (with `Idempotent-Replayed: true`).

## Request

<CodeGroup>
  ```bash cURL theme={null}
  curl -X POST https://api.fireflo.au/v1/webhooks \
    -H "Authorization: Bearer $OMNI_API_KEY" \
    -H "Content-Type: application/json" \
    -H "Idempotency-Key: webhook-order-service" \
    -d '{
      "url": "https://hooks.acme.in/omni",
      "description": "Order service",
      "events": [
        "message.succeeded",
        "message.failed"
      ]
    }'
  ```

  ```python Python theme={null}
  import os

  import requests

  response = requests.post(
      "https://api.fireflo.au/v1/webhooks",
      headers={
          "Authorization": f"Bearer {os.environ['OMNI_API_KEY']}",
          "Idempotency-Key": "webhook-order-service",
      },
      json={
          "url": "https://hooks.acme.in/omni",
          "description": "Order service",
          "events": ["message.succeeded", "message.failed"],
      },
  )
  print(response.status_code, response.json())
  ```

  ```javascript Node theme={null}
  const response = await fetch("https://api.fireflo.au/v1/webhooks", {
    method: "POST",
    headers: {
      Authorization: `Bearer ${process.env.OMNI_API_KEY}`,
      "Content-Type": "application/json",
      "Idempotency-Key": "webhook-order-service",
    },
    body: JSON.stringify({
      "url": "https://hooks.acme.in/omni",
      "description": "Order service",
      "events": [
        "message.succeeded",
        "message.failed"
      ]
    }),
  });
  console.log(response.status, await response.json());
  ```
</CodeGroup>

## Response

`201 Created` — the endpoint, with `secret`. `events` comes back sorted, without repeats.

```json theme={null}
{
  "id": "c4e8f2a6-1b3d-4c5e-9f7a-8b6d4e2c0a19",
  "url": "https://hooks.acme.in/omni",
  "description": "Order service",
  "events": [
    "message.failed",
    "message.succeeded"
  ],
  "enabled": true,
  "failing_since": null,
  "disabled_reason": "",
  "created": "2026-09-12T08:02:51.774Z",
  "secret": "whsec_Jx3m9QpV7r2LkT8wYc5nB1dHf6sZa4Ge0uNoPiRtXyE"
}
```

## Errors

Every refusal is `{"error": {"code", "message", "field"}}`; `field` is there when one input is at fault.

| Status | Error code | When |
| :- | :- | :- |
| 400 | `invalid_request` | An input is wrong: not an `https://` address, an address that isn't public, an unknown event, an empty `events` (`field` names it). |
| 400 | `invalid_json` | The body isn't valid JSON. |
| 403 | `scope_missing` | The key doesn't have the `webhooks:write` scope. |

Any request can also be refused for its key, its account or its rate (`key_required`, `invalid_key`, `account_suspended`, `plan_excludes_api`, `address_not_allowed`, `rate_limited`); see [the overview](/api-reference/overview).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.