1. Docs
  2. API Reference
  3. Create a webhook subscription

Create a webhook subscription

POST/portal/v1/accounts/{accountSlug}/webhooks

Creates a webhook subscription for the active Application's current Environment from a url, an event_types array, and an optional description. Use ["*"] to subscribe to all events (current and future); the wildcard cannot be mixed with concrete types, and any unsupported event type returns 400. The response includes a freshly minted HMAC signing secret that is shown only once at creation — store it to verify delivery signatures. Requires the webhook.manage permission.

Authentication

Bearer TokenAuthorization

JWT access token. Never send alongside X-API-Key: a request carrying both is refused.

Requires capability account_webhooks.manageAccount

Manage account-tier webhook subscriptions. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.

Request body

application/json

urlstring Required
event_typesstring[] Required
descriptionstring Optional

Responses

application/json

  • dataWebhookCreatedResponseDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

Errors

When the request can't be completed, the response body includes a stable error code you can branch on.

403account.capability_requiredForbidden
When it happens

The signed-in user's administrator roles do not grant the capability this endpoint requires.

Remediation

Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.

Returned object

Request
curl -X POST "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/webhooks" \
  -H "Authorization: Bearer $CANOPY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "string",
    "event_types": [
      "string"
    ],
    "description": "string"
  }'
Response
{
  "data": {
    "id": "string",
    "scope": "environment",
    "url": "string",
    "event_types": [
      "string"
    ],
    "description": "string",
    "is_active": false,
    "created_at": "2026-04-20T12:00:00.000Z",
    "secret": "string"
  }
}
Related endpoints
GETList webhook subscriptions
GETActive/inactive webhook counts for the environment
GETList subscribable webhook event types
GETList delivery attempts for a webhook
GETGet a webhook subscription
PATCHUpdate a webhook subscription
DELETEDelete a webhook subscription
POSTRotate a webhook subscription's signing secret
Was this page helpful?

Tell us how we can improve this guide.