Zernio
Zernio
API Reference

Webhooks

Create webhookPOSTList webhook delivery logsGETList webhooksGETUpdate webhookPUTDelete webhookDELETERedeliver a webhook eventPOSTSend test webhookPOST
Dashboard
llms.txtOpenAPI
OverviewPlatformsAPI ReferenceResources
Webhooks

Update webhook

Update an existing webhook configuration. All fields except _id are optional; only provided fields will be updated.

When provided, name must be 1-50 characters, url must be a valid URL, and events must contain at least one event. Whitespace is trimmed from url before validation.

Webhooks are auto-disabled only once the endpoint has had no successful delivery for 3 days AND has either reached 20 consecutive terminal failures (each one an event that exhausted the full retry ladder) or been failing continuously for 3 days. The owner is emailed; re-enable it with isActive: true.

A restricted (zrk_) API key can only set events to events whose resource group the key holds; an event outside the key's groups is rejected with 403. It also cannot widen an existing subscription past its own groups.

disabledResourceGroups replaces the subscription's own denylist, which applies to delivery regardless of which key or session created it. Send an empty array to clear it. A restricted key's own disabled groups are unioned into the stored value on every update, so repointing a legacy unrestricted subscription with a restricted key also narrows it.

Timing: the new denylist applies to every event emitted after the update. Events already queued for delivery when the update landed were filtered against the previous denylist and can still arrive at your endpoint for up to five minutes after they were enqueued, because the delivery worker trusts a five-minute enqueue-time snapshot before re-checking the subscription. Retries beyond that window, dead-letter replays, test fires, and redeliveries are all checked against the current denylist.


PUT
/v1/webhooks/settings

Authorization

bearerAuth
AuthorizationBearer <token>

API key authentication: send your Zernio API key in the Authorization header, prefixed with Bearer.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

{  "success": true,  "webhook": {    "_id": "string",    "name": "string",    "url": "http://example.com",    "secret": "string",    "events": [      "post.scheduled"    ],    "isActive": true,    "lastFiredAt": "2019-08-24T14:15:22Z",    "failureCount": 0,    "customHeaders": {      "property1": "string",      "property2": "string"    },    "disabledResourceGroups": [      "publishing"    ]  }}
Was this page helpful?

List webhooks

Retrieve all configured webhooks for the authenticated user. Supports up to 50 webhooks per user.

Delete webhook

Permanently delete a webhook configuration.

_id*string

Webhook ID to update (required)

name?string

Webhook name (1-50 characters). Must be non-empty if provided.

Length1 <= length <= 50
url?string

Webhook endpoint URL (must be a valid URL, whitespace trimmed). Must be a valid URL if provided.

Formaturi
secret?string

Secret key for HMAC-SHA256 signature verification

events?array<>

Events to subscribe to. Must contain at least one event if provided.

Items1 <= items
isActive?boolean

Enable or disable webhook delivery

customHeaders?

Custom headers to include in webhook requests

disabledResourceGroups?array<>

Replaces the subscription's denylist. Send an empty array to clear it and receive every event in events again. Omitting the field leaves the current denylist untouched. Applies to events emitted after the update; already-queued events can still deliver for up to five minutes after they were enqueued. When the caller is a restricted (zrk_) key, that key's own disabled groups are unioned back in either way, so a restricted key can neither clear nor widen a subscription past its own groups.