Skip to main content
POST
Create a webhook subscription

Authorizations

DPoP
string
header
required

Per-request DPoP proof JWT (RFC 9449). MUST accompany the Authorization: DPoP <access_token> header on every protected operation. The proof is signed by the merchant's private DPoP key and carries htm, htu, iat, jti, and ath claims.

Headers

Idempotency-Key
string
required

Unique key identifying this operation. Sending the same key twice returns the original response instead of creating a duplicate. Keys are retained for 24 hours.

Maximum string length: 255

Body

application/json
url
string<uri>
required

HTTPS URL that will receive deliveries.

Example:

"https://example.com/webhooks/anton"

events
enum<string>[]
required

Event types this subscription should receive. Use ["*"] to subscribe to everything.

See Webhook Events for the full catalog and payload shapes. Some reserved event types (balance.low on some paths) may be defined but not yet dispatched — subscribing to them is safe but no deliveries arrive until they're wired up.

Available options:
payout.created,
payout.approved,
payout.processing,
payout.sent,
payout.completed,
payout.failed,
payout.cancelled,
payout.returned,
payout.screening_failed,
payout.velocity_blocked,
payout.engine_blocked,
beneficiary.created,
beneficiary.updated,
beneficiary.deleted,
beneficiary.blocked,
instrument.created,
instrument.updated,
instrument.deleted,
batch.uploaded,
batch.completed,
batch.failed,
fx.quote.created,
fx.exchange.created,
fx.exchange.completed,
fx.exchange.failed,
funding.credit,
screening.hit,
intelligence.evaluation.completed,
intelligence.evaluation.failed,
balance.low,
test
metadata
object

Response

Subscription created. Includes the one-time signing secret.

A registered webhook endpoint and its event filter.

id
string
required
Pattern: ^whk_[a-zA-Z0-9]+$
Example:

"whk_01HX8Z9K0M2N3P4Q5R6S7T8UW"

merchant_id
string
required
Pattern: ^mer_[a-zA-Z0-9]+$
url
string<uri>
required
events
enum<string>[]
required

See Webhook Events for the full catalog and payload shapes. Some reserved event types (balance.low on some paths) may be defined but not yet dispatched — subscribing to them is safe but no deliveries arrive until they're wired up.

Available options:
payout.created,
payout.approved,
payout.processing,
payout.sent,
payout.completed,
payout.failed,
payout.cancelled,
payout.returned,
payout.screening_failed,
payout.velocity_blocked,
payout.engine_blocked,
beneficiary.created,
beneficiary.updated,
beneficiary.deleted,
beneficiary.blocked,
instrument.created,
instrument.updated,
instrument.deleted,
batch.uploaded,
batch.completed,
batch.failed,
fx.quote.created,
fx.exchange.created,
fx.exchange.completed,
fx.exchange.failed,
funding.credit,
screening.hit,
intelligence.evaluation.completed,
intelligence.evaluation.failed,
balance.low,
test
status
enum<string>
required
Available options:
active,
inactive
version
string
required

API version this subscription pins to.

Example:

"2024-01-01"

created_at
string<date-time>
required

RFC 3339 / ISO 8601 timestamp in UTC.

Example:

"2026-04-15T14:30:00Z"

updated_at
string<date-time>
required

RFC 3339 / ISO 8601 timestamp in UTC.

Example:

"2026-04-15T14:30:00Z"

metadata
object
secret
string

Signing secret (whsec_ + 64 hex). Shown once — store it now.

Example:

"whsec_0a1b2c3d4e5f67890123456789abcdef0123456789abcdef0123456789abcdef"