curl --request PATCH \
--url https://app.thinnest.ai/api/v1/webhooks/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"enabled": true,
"events": [
"call.analysed",
"call.completed",
"lead.captured"
]
}
'const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({enabled: true, events: ['call.analysed', 'call.completed', 'lead.captured']})
};
fetch('https://app.thinnest.ai/api/v1/webhooks/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/webhooks/{id}"
payload = {
"enabled": True,
"events": ["call.analysed", "call.completed", "lead.captured"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"id": "wh_e1c5a7d2-9b3f-4c86-a0e4-5d2b7f913c08",
"agent": "ag_3f6a9c21-7d4e-4b58-9a1f-0c2e8b7d5a34",
"includeCustomers": false,
"url": "https://crm.sunrisedental.in/hooks/agent",
"events": [
"call.analysed",
"call.completed",
"lead.captured"
],
"enabled": true,
"delivery": {
"failuresInARow": 0,
"lastStatus": 500,
"lastError": null,
"lastSentAt": "2026-10-06T09:12:03.551Z"
},
"createdAt": "2026-09-17T09:41:00.210Z"
}{
"error": "`events` cannot be empty — name at least one, or leave it out for all."
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "This API key is read-only: it can read everything but change nothing."
}{
"error": "That endpoint was not found."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}{
"error": "Could not save the endpoint."
}Update Webhook
Changes an endpoint’s url, events or enabled; fields you leave out are kept. Switching an endpoint back on (enabled: true) forgives its past failures, so after an outage: fix the receiver, catch up from the API on what it missed, then PATCH { "enabled": true }. The agent an endpoint belongs to cannot be changed. A build key may do this.
curl --request PATCH \
--url https://app.thinnest.ai/api/v1/webhooks/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"enabled": true,
"events": [
"call.analysed",
"call.completed",
"lead.captured"
]
}
'const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({enabled: true, events: ['call.analysed', 'call.completed', 'lead.captured']})
};
fetch('https://app.thinnest.ai/api/v1/webhooks/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/webhooks/{id}"
payload = {
"enabled": True,
"events": ["call.analysed", "call.completed", "lead.captured"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"id": "wh_e1c5a7d2-9b3f-4c86-a0e4-5d2b7f913c08",
"agent": "ag_3f6a9c21-7d4e-4b58-9a1f-0c2e8b7d5a34",
"includeCustomers": false,
"url": "https://crm.sunrisedental.in/hooks/agent",
"events": [
"call.analysed",
"call.completed",
"lead.captured"
],
"enabled": true,
"delivery": {
"failuresInARow": 0,
"lastStatus": 500,
"lastError": null,
"lastSentAt": "2026-10-06T09:12:03.551Z"
},
"createdAt": "2026-09-17T09:41:00.210Z"
}{
"error": "`events` cannot be empty — name at least one, or leave it out for all."
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "This API key is read-only: it can read everything but change nothing."
}{
"error": "That endpoint was not found."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}{
"error": "Could not save the endpoint."
}Authorizations
Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.
Headers
Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace.
"org_3fKq9TzQ1mN8vB2xR7cLpA"
Path Parameters
The endpoint's id (wh_…).
Body
Send at least one field.
A new https:// URL or email address.
"https://crm.sunrisedental.in/hooks/agent-v2"
The events to send from now on. Naming every event means every event, now and as new ones are added.
1An event a webhook endpoint can subscribe to.
lead.captured, conversation.escalated, conversation.resolved, call.completed, call.analysed, campaign.finished [
"call.analysed",
"call.completed",
"lead.captured"
]
false stops sending; true starts again and forgives past failures.
true
Response
The endpoint as it now is.
An endpoint an agent's events are sent to.
The endpoint's id (wh_…).
"wh_e1c5a7d2-9b3f-4c86-a0e4-5d2b7f913c08"
The agent whose events it receives (ag_…); null for an endpoint that receives every customer's events (includeCustomers).
"ag_3f6a9c21-7d4e-4b58-9a1f-0c2e8b7d5a34"
Whether it receives the events of every agent in every one of this developer's customers, each delivery's data naming the customer as workspaceId.
false
Where events go: an https:// URL or an email address.
"https://crm.sunrisedental.in/hooks/agent"
The events it receives. ["*"] means every event, now and as new ones are added.
*, lead.captured, conversation.escalated, conversation.resolved, call.completed, call.analysed, campaign.finished ["call.analysed", "lead.captured"]
Whether events are sent to it. Turned off by itself after five failed deliveries in a row.
true
How delivering to it has gone.
Show child attributes
Show child attributes
"2026-09-17T09:41:00.210Z"