curl --request POST \
--url https://app.trackplay.io/api/v1/webhooks \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "<string>",
"url": "<string>",
"events": [],
"secret": "<string>"
}
'import requests
url = "https://app.trackplay.io/api/v1/webhooks"
payload = {
"name": "<string>",
"url": "<string>",
"events": [],
"secret": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({name: '<string>', url: '<string>', events: [], secret: '<string>'})
};
fetch('https://app.trackplay.io/api/v1/webhooks', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.trackplay.io/api/v1/webhooks",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'url' => '<string>',
'events' => [
],
'secret' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.trackplay.io/api/v1/webhooks"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"url\": \"<string>\",\n \"events\": [],\n \"secret\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.trackplay.io/api/v1/webhooks")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"url\": \"<string>\",\n \"events\": [],\n \"secret\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.trackplay.io/api/v1/webhooks")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"url\": \"<string>\",\n \"events\": [],\n \"secret\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"webhook": {
"id": 123,
"workspace_id": 123,
"name": "<string>",
"url": "<string>",
"events": [
"<string>"
],
"is_active": true,
"last_success_at": "2023-11-07T05:31:56Z",
"last_failure_at": "2023-11-07T05:31:56Z",
"failure_count": 123,
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"message": "The given data was invalid.",
"errors": {}
}Create a webhook subscription
Subscribes a URL to one or more lifecycle events. Every delivery is a signed POST carrying X-Trackplay-Event, X-Trackplay-Signature (an HMAC-SHA256 of the payload using the subscription’s secret), and X-Trackplay-Timestamp.
secret is never returned by the API, not even in the response to this call: the model hides it from every JSON response, always. If you omit it, one is generated for you, but there is then no way to retrieve it afterward, so you cannot verify a signature against it. Always send your own secret if you plan to verify delivery signatures.
Requires a token with the webhooks:write scope.
curl --request POST \
--url https://app.trackplay.io/api/v1/webhooks \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "<string>",
"url": "<string>",
"events": [],
"secret": "<string>"
}
'import requests
url = "https://app.trackplay.io/api/v1/webhooks"
payload = {
"name": "<string>",
"url": "<string>",
"events": [],
"secret": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({name: '<string>', url: '<string>', events: [], secret: '<string>'})
};
fetch('https://app.trackplay.io/api/v1/webhooks', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.trackplay.io/api/v1/webhooks",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'url' => '<string>',
'events' => [
],
'secret' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.trackplay.io/api/v1/webhooks"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"url\": \"<string>\",\n \"events\": [],\n \"secret\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.trackplay.io/api/v1/webhooks")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"url\": \"<string>\",\n \"events\": [],\n \"secret\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.trackplay.io/api/v1/webhooks")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"url\": \"<string>\",\n \"events\": [],\n \"secret\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"webhook": {
"id": 123,
"workspace_id": 123,
"name": "<string>",
"url": "<string>",
"events": [
"<string>"
],
"is_active": true,
"last_success_at": "2023-11-07T05:31:56Z",
"last_failure_at": "2023-11-07T05:31:56Z",
"failure_count": 123,
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"message": "The given data was invalid.",
"errors": {}
}Authorizations
A scoped token minted in Settings → API tokens. Send it as Authorization: Bearer tplt_… or X-API-Key: tplt_….
Headers
Retry-safe key. The first response for a given key is cached for 24 hours and replayed on a repeat, with Idempotency-Replayed: true set.
Body
128Where deliveries are POSTed.
2048Which events this subscription fires on. Every entry must be one of the supported event names.
1video.created, video.uploaded, video.settings.deployed, video.deleted, video.viewed, conversion, conversion.created, play, play.milestone, cta.clicked, ended, lead.captured, lesson.completed, playlist.ended, lead_form.submitted, quiz.answered, split_test.winner_declared Used to HMAC-SHA256 sign deliveries in the X-Trackplay-Signature header. Generated for you if omitted, but a generated secret can never be read back, only rotated by deleting and recreating the subscription. Send your own if you need to know it ahead of time.
16 - 128Response
The subscription. secret is not included, even if you sent one yourself: keep your own copy.
A webhook subscription. secret is never included in any response, including the response to the call that created it: the value is write-only. If you did not set your own secret on creation, save the one you sent, because a server-generated secret cannot be read back later.
Show child attributes
Show child attributes