1. Docs
  2. API Reference
  3. Update a webhook subscription

Update a webhook subscription

PATCH/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/webhooks/{id}

Updates a webhook subscription's url, event_types, description, and/or is_active flag by id; omitted fields are left unchanged. When event_types is provided it is re-validated against the Environment's registry, and an unsupported type returns 400 (wildcard rules apply). Returns 404 for a subscription outside this Environment and requires the webhook.manage permission; the signing secret is not affected or returned.

Authentication

Bearer TokenAuthorization

JWT access token. Never send alongside X-API-Key: a request carrying both is refused.

Requires capability env_webhooks.manageDeveloper Console

Create, edit, rotate, and delete Environment webhook subscriptions. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.

Path Parameters

idstring Required

Request body

application/json

urlstring Optional
event_typesstring[] Optional
descriptionstring Optional
is_activeboolean Optional

Responses

application/json

  • dataWebhookResponseDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

Errors

When the request can't be completed, the response body includes a stable error code you can branch on.

403account.capability_requiredForbidden
When it happens

The signed-in user's administrator roles do not grant the capability this endpoint requires.

Remediation

Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.

Returned object

Request
curl -X PATCH "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/webhooks/value" \
  -H "Authorization: Bearer $CANOPY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "string",
    "event_types": [
      "string"
    ],
    "description": "string",
    "is_active": false
  }'
Response
{
  "data": {
    "id": "string",
    "scope": "environment",
    "url": "string",
    "event_types": [
      "string"
    ],
    "description": "string",
    "is_active": false,
    "created_at": "2026-04-20T12:00:00.000Z"
  }
}
Related endpoints
GETList webhook subscriptions
POSTCreate a webhook subscription
GETActive/inactive webhook counts for the environment
GETList subscribable webhook event types
GETList delivery attempts for a webhook
GETGet a webhook subscription
DELETEDelete a webhook subscription
POSTRotate a webhook subscription's signing secret
Was this page helpful?

Tell us how we can improve this guide.