Skip to main content
This page is about managing subscriptions: creating them, listing them, deleting them, and firing a test delivery. For what a delivery looks like on the wire, headers, signature, retries, see Webhooks. That page does not change here; this one only adds an API for the same subscriptions it describes. Every call on this page needs a token with webhooks:write.

List subscriptions and the event catalogue

curl
200 OK
supported_events is the exact, complete list POST /v1/webhooks will accept in events[]. Nothing outside it is valid.
A subscription’s secret never appears in this list, or anywhere else this API returns a subscription. See the warning below.

Create a subscription

string
required
Max 128 characters.
string
required
A valid URL, max 2048 characters.
string[]
required
At least one event, each from the supported_events list above.
string
16 to 128 characters. If you omit it, the server generates one with no fixed prefix.
The response never includes secret, not even on creation, not even if you generated it yourself. The subscription model hides that field on every response this API returns, with no exception for the create call. If you supply your own secret, this costs you nothing, you already have it. If you omit it and let the server generate one, you have no way to read it back through this API, ever, and you cannot verify a delivery’s signature without it. Always send your own secret (16 to 128 characters, generated and stored on your side) rather than relying on the server-generated one.
201 Created

Delete a subscription

curl
200 OK

Send a test delivery

curl
200 OK
502 Bad Gateway
This sends a real webhook.test payload to the subscription’s URL, signed the same way a live delivery is. Unlike a live delivery, it is attempted exactly once: a failed test is not queued for retry. You get the failure reason back inline instead, which is the point, it is meant for debugging your endpoint, not for exercising the retry path. See Webhooks for how a real delivery’s retries work.

Zapier REST hooks

The Zapier integration runs on the same webhooks:write token, supplied as the connection’s “API Key” field, and every subscription it creates is a normal webhook subscription under the hood.
All five Zapier routes below, including the three GETs, share the write rate limit: 60 requests per minute per token, not the 600-per-minute read tier the rest of this API gives GET calls.

Connection test

curl
200 OK

Trigger catalogue

curl
200 OK
key is the Zapier trigger identifier. event is the internal webhook event name it maps to. They are different strings, new_lead versus lead.captured, and the two calls below expect different ones: subscribe and sample take the trigger key, the internal event name is not valid input to either.

Sample payload

curl
200 OK
An unknown trigger key returns {"error": "unknown_trigger"}, a flat string, not the {"error": {"code": ...}} object shape every other endpoint on this page uses.

Subscribe

string
required
A valid URL, max 2048 characters. This is the Zap’s hook URL.
string
required
A trigger key from the catalogue above (new_lead, not lead.captured).
curl
201 Created
The response echoes back the internal event name, not the trigger key you sent. This creates a normal webhook subscription behind the scenes, named Zapier: New Lead, with its own generated secret, the same “you cannot read it back” caveat above applies here too.

Unsubscribe

curl
200 OK
Returns {"deleted": true} whether or not that id existed. There is no 404 from this call.

Errors

The token is wrong, expired, or revoked.
Every call on this page needs webhooks:write.
No subscription with that id in your workspace, on DELETE /v1/webhooks/{webhook} or POST /v1/webhooks/{webhook}/test. Laravel’s default body: {"message": "No query results for model [App\\Models\\WebhookSubscription] 9"}.
Validation failed on create or subscribe, most often an events[] value outside supported_events, or a secret shorter than 16 characters.
A test delivery could not reach the subscription’s URL. {"delivered": false, "error": "<reason>"}.
Rate limited. 60 requests per minute per token, on every call on this page including the Zapier GETs.