Skip to main content
POST
Create a webhook subscription

Authorizations

Authorization
string
header
required

A scoped token minted in Settings → API tokens. Send it as Authorization: Bearer tplt_… or X-API-Key: tplt_….

Headers

Idempotency-Key
string

Retry-safe key. The first response for a given key is cached for 24 hours and replayed on a repeat, with Idempotency-Replayed: true set.

Body

application/json
name
string
required
Maximum string length: 128
url
string<uri>
required

Where deliveries are POSTed.

Maximum string length: 2048
events
enum<string>[]
required

Which events this subscription fires on. Every entry must be one of the supported event names.

Minimum array length: 1
Available options:
video.created,
video.uploaded,
video.settings.deployed,
video.deleted,
video.viewed,
conversion,
conversion.created,
play,
play.milestone,
cta.clicked,
ended,
lead.captured,
lesson.completed,
playlist.ended,
lead_form.submitted,
quiz.answered,
split_test.winner_declared
secret
string

Used to HMAC-SHA256 sign deliveries in the X-Trackplay-Signature header. Generated for you if omitted, but a generated secret can never be read back, only rotated by deleting and recreating the subscription. Send your own if you need to know it ahead of time.

Required string length: 16 - 128

Response

The subscription. secret is not included, even if you sent one yourself: keep your own copy.

webhook
object

A webhook subscription. secret is never included in any response, including the response to the call that created it: the value is write-only. If you did not set your own secret on creation, save the one you sent, because a server-generated secret cannot be read back later.