Skip to main content
POST
Create Webhook

Authorizations

Authorization
string
header
required

Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.

Headers

Thinnest-Workspace
string

Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace.

Example:

"org_3fKq9TzQ1mN8vB2xR7cLpA"

Body

application/json
url
string
required

An https:// URL, or an email address for a helpdesk that opens tickets by mail. Addresses inside our own network are refused.

Example:

"https://crm.sunrisedental.in/hooks/agent"

agent
string

The agent whose events to send (ag_…). Required unless includeCustomers is true; never with it.

Example:

"ag_3f6a9c21-7d4e-4b58-9a1f-0c2e8b7d5a34"

includeCustomers
boolean
default:false

Developer workspaces only: one endpoint for the events of every agent in every one of your customers. Send it instead of agent.

Example:

false

events
enum<string>[]

Which events to send. Leave it out for every event, now and as new ones are added (the endpoint then reads ["*"]); naming all of them means the same.

Minimum array length: 1

An event a webhook endpoint can subscribe to.

Available options:
lead.captured,
conversation.escalated,
conversation.resolved,
call.completed,
call.analysed,
campaign.finished
Example:
enabled
boolean
default:true

Whether to start sending at once.

Example:

true

Response

The endpoint, with its signing secret shown this once.

A new endpoint, with its signing secret.

id
string
required

The endpoint's id (wh_…).

Example:

"wh_e1c5a7d2-9b3f-4c86-a0e4-5d2b7f913c08"

agent
string | null
required

The agent whose events it receives (ag_…); null for an endpoint that receives every customer's events (includeCustomers).

Example:

"ag_3f6a9c21-7d4e-4b58-9a1f-0c2e8b7d5a34"

includeCustomers
boolean
required

Whether it receives the events of every agent in every one of this developer's customers, each delivery's data naming the customer as workspaceId.

Example:

false

url
string
required

Where events go: an https:// URL or an email address.

Example:

"https://crm.sunrisedental.in/hooks/agent"

events
enum<string>[]
required

The events it receives. ["*"] means every event, now and as new ones are added.

Available options:
*,
lead.captured,
conversation.escalated,
conversation.resolved,
call.completed,
call.analysed,
campaign.finished
Example:
enabled
boolean
required

Whether events are sent to it. Turned off by itself after five failed deliveries in a row.

Example:

true

delivery
object
required

How delivering to it has gone.

createdAt
string<date-time>
required
Example:

"2026-09-17T09:41:00.210Z"

signingSecret
string
required

The secret every delivery's x-thinnest-signature is an HMAC-SHA256 under. In this response only — store it.

Example:

"q7Vb2LmX9cTz4RkP1sWd8HfN3yJe6GaU"