Esc

↑↓ move↵ openIndex · Pagefind
API preview · design draft
API reference · Platform

Webhook endpoints

Where we send events. Subscribe to the state changes you care about; every delivery is signed.

Design draftSubject to changeobject: webhook_endpointid prefix: we_
  1. OBJECT The webhook_endpoint object
  2. POST /v1/webhooksCreate an endpoint
  3. GET /v1/webhooksList endpoints
  4. DELETE /v1/webhooks/{id}Delete an endpoint

The webhook_endpoint object

Every object carries an id, timestamps, and an audit_trail. Money is integer cents. Expand any node in the explorer to see how it links to the rest of the record.

  • id
    string
    Unique, stable identifier. Prefixed by object type.
  • object
    string
    String naming the object type.
  • url
    string
    HTTPS URL that receives POSTs.
  • status
    enum
    enabled · disabled.
  • events
    array
    Event types, or ["*"].
  • description
    string
    Your label.
  • secret
    string
    Signing secret. Shown in full once, on create.
  • api_version
    string
    Payload version pinned at create.
  • created_at
    timestamp
    ISO 8601, UTC.
  • updated_at
    timestamp
    ISO 8601, UTC. Changes on every write.
  • audit_trail
    string
    Path to the append-only history of who changed what, and when.
webhook_endpoint · sample data
object{11}
  • id"we_7Hq2"id
  • object"webhook_endpoint"string
  • url"https://erp.example.com/hooks/os"string
  • status"enabled"string
  • eventsarray[3]
    • 0"change_order.approved"string
    • 1"pay_app.submitted"string
    • 2"invoice.coded"string
  • description"ERP sync"string
  • secret"whsec_••••••••3f9a"string
  • api_version"2026-10-preview"string
  • created_at"2026-10-01T12:00:00Z"timestamp
  • updated_at"2026-10-01T12:00:00Z"timestamp
  • audit_trail"/v1/webhooks/we_7Hq2/audit"string
POST /v1/webhooks

Create an endpoint

Returns the full secret once.

Idempotent. Send an Idempotency-Key; retries within 24 hours return the original result and never write twice.

Parameters

  • Idempotency-Key
    stringheaderrequired
    Any unique string. Replays return the first result instead of writing twice.
  • url
    stringbodyrequired
    HTTPS URL.
  • events
    arraybodyrequired
    Event types.

Returns

The webhook_endpoint object. Errors use the standard error shape.

Request
curl -X POST https://api.os.construction/v1/webhooks \
  -H "Authorization: Bearer $OS_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://erp.example.com/hooks/os",
    "events": [
      "change_order.approved",
      "pay_app.submitted",
      "invoice.coded"
    ],
    "description": "ERP sync"
  }'
Response · 201
{
  "id": "we_7Hq2",
  "object": "webhook_endpoint",
  "url": "https://erp.example.com/hooks/os",
  "status": "enabled",
  "events": [
    "change_order.approved",
    "pay_app.submitted",
    "invoice.coded"
  ],
  "description": "ERP sync",
  "secret": "whsec_5b1e0c7d9a2f4e3f9a",
  "api_version": "2026-10-preview",
  "created_at": "2026-10-01T12:00:00Z",
  "updated_at": "2026-10-01T12:00:00Z",
  "audit_trail": "/v1/webhooks/we_7Hq2/audit"
}
GET /v1/webhooks

List endpoints

All endpoints on the account.

Parameters

  • limit
    integerquery
    Page size, 1 to 100. Default 25.
  • cursor
    stringquery
    Cursor from a previous page’s next_cursor.

Returns

A paginated list of webhook_endpoint objects. Errors use the standard error shape.

Request
curl https://api.os.construction/v1/webhooks \
  -H "Authorization: Bearer $OS_API_KEY"
Response · 200
{
  "object": "list",
  "url": "/v1/webhooks",
  "has_more": false,
  "next_cursor": null,
  "data": [
    {
      "id": "we_7Hq2",
      "object": "webhook_endpoint",
      "url": "https://erp.example.com/hooks/os",
      "status": "enabled",
      "events": [
        "change_order.approved",
        "pay_app.submitted",
        "invoice.coded"
      ],
      "description": "ERP sync",
      "secret": "whsec_••••••••3f9a",
      "api_version": "2026-10-preview",
      "created_at": "2026-10-01T12:00:00Z",
      "updated_at": "2026-10-01T12:00:00Z",
      "audit_trail": "/v1/webhooks/we_7Hq2/audit"
    }
  ]
}
DELETE /v1/webhooks/{id}

Delete an endpoint

Stops deliveries immediately.

Parameters

  • id
    stringpathrequired
    The webhook endpoint ID, e.g. we_7Hq2.

Returns

A deletion confirmation. Errors use the standard error shape.

Request
curl -X DELETE https://api.os.construction/v1/webhooks/we_7Hq2 \
  -H "Authorization: Bearer $OS_API_KEY"
Response · 200
{
  "id": "we_7Hq2",
  "object": "webhook_endpoint",
  "deleted": true
}