Create a webhook endpoint
Subscribe a new URL to events for this account. The signingSecret is included in the response exactly once — store it now. To rotate, delete the endpoint and create a new one. URLs must be HTTPS in production (HTTP allowed only for localhost during local development). Pass an Idempotency-Key for safe retries.
Authorizations
Bearer API key. Two modes: sv_live_* for production data, sv_test_* for a parallel sandbox dataset that doesn't count against plan limits. Issued from Settings → Developers in the SiteVisit app.
Headers
Optional idempotency key, scoped to the authenticated account. Repeating a write with the same key + same body returns the original response; same key + different body returns 422 idempotency_key_in_use.
255Body
Display label shown in Settings → Developers + on delivery logs.
1 - 100HTTPS endpoint to POST events to. HTTP allowed only for localhost URLs in development.
Subset of event types to subscribe to. Omit or pass [] to subscribe to all event types — useful for a generic ingest endpoint.
Response
Endpoint created. Response includes the signingSecret exactly once.
Events this endpoint subscribes to. An empty array means all events — the endpoint will receive every event type. See the Webhooks guide for the full event catalogue.
Which traffic class this endpoint receives. live endpoints fire on real customer activity; test endpoints only fire on activity triggered by sv_test_* API keys. Lets integrators wire a localhost endpoint against test mode without it ever receiving real-customer traffic.
live, test When true, the endpoint is paused — events are not delivered, but the row + signing secret remain so it can be re-enabled later.
Secret used to verify webhook signatures (HMAC-SHA256, Stripe pattern). Shown exactly once at creation — store it now. Rotate by deleting + recreating the endpoint.