Skip to content

Update Endpoint

PATCH
/api/webhooks/endpoints/{endpoint_uuid}
curl --request PATCH \
--url https://app.lionrapid.com/api/webhooks/endpoints/example \
--header 'Content-Type: application/json' \
--data '{ "events": [ "example" ], "namespaces": [ "example" ] }'

Change the subscription filters. PATCH, not PUT: an omitted field is untouched, so a client that only knows about one filter cannot blank the other. Returns the list item — changing a filter is not an occasion to re-disclose the secret.

endpoint_uuid
required
Endpoint Uuid
string
Media typeapplication/json
UpdateWebhookEndpointRequest

The subscription filters, changeable after creation.

WITHOUT THIS, SCOPING IS SET-ONCE. The only other way to change what an endpoint listens to would be delete-and-recreate, which mints a new endpoint_uuid and therefore DISCARDS the delivery observations keyed on it — the same data-loss trade the rotate route exists to avoid for secrets. Narrowing a subscription is an ordinary thing to want to do twice.

Both fields are optional and only what is sent is written, so a client that knows about one filter cannot blank the other by omitting it.

object
events
Any of:
Array<string>
namespaces
Any of:
Array<string>
Examplegenerated
{
"events": [
"example"
],
"namespaces": [
"example"
]
}

Successful Response

Media typeapplication/json
WebhookEndpointListItem

An endpoint WITHOUT its HMAC secret. What listing returns.

THE SECRET IS SHOW-ONCE (#190 follow-up). It used to ride on every list call, which meant a single leaked list response disclosed the signing key for every endpoint in the project. It is now returned by CREATE and by ROTATE only, which is the convention this product already uses for sk_ integration keys.

THE ORDER MATTERED: rotation landed FIRST, in the same change. Dropping it from list without a way to mint a new one would have left an operator who lost the secret with delete-and-recreate as their only recovery — discarding endpoint_uuid and, with it, the delivery observations keyed on that uuid. Show-once without rotation trades a disclosure problem for a data-loss one.

WebhookEndpointResponse extends this with secret rather than repeating the fields, so the list shape cannot silently regrow one: adding a field here adds it to both, and adding a secret means editing the subclass on purpose.

object
endpoint_uuid
required
Endpoint Uuid
string
url
required
Url
string
format
required
Format
string
events
required
Events
Array<string>
namespaces
required
Namespaces
Array<string>
active
required
Active
boolean
created_at
required
Created At
number
last_delivery_channel
Any of:
string
last_delivery_outcome
Any of:
string
last_delivery_at
Any of:
number
last_delivery_ok_at
Any of:
number
consecutive_delivery_failures
Any of:
integer
Examplegenerated
{
"endpoint_uuid": "example",
"url": "example",
"format": "example",
"events": [
"example"
],
"namespaces": [
"example"
],
"active": true,
"created_at": 1,
"last_delivery_channel": "example",
"last_delivery_outcome": "example",
"last_delivery_at": 1,
"last_delivery_ok_at": 1,
"consecutive_delivery_failures": 1
}

Validation Error

Media typeapplication/json
HTTPValidationError
object
detail
Detail
Array<object>
ValidationError
object
loc
required
Location
Array
msg
required
Message
string
type
required
Error Type
string
Examplegenerated
{
"detail": [
{
"loc": [
"example"
],
"msg": "example",
"type": "example"
}
]
}