POST
/v1/webhooksCreate a webhook subscription
Registers an endpoint. Set scope to account to receive events from every profile through one endpoint. The signing secret is returned once.
Required permission: `webhooks:write`
Accepts `profileId` to target a specific profile. Omit it to use the key’s home profile.
- Base URL
- https://api.cutedyno.com
- Permission
webhooks:write- Idempotency
- Send an
Idempotency-Keyheader so a retry cannot apply twice. How it works - MCP tool
- create_webhook
Request
curl -X POST "https://api.cutedyno.com/v1/webhooks" \
-H "Authorization: Bearer $CUTEDYNO_API_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{
"profileId": "profile_a1b2c3d4",
"url": "https://cdn.example.com/media/launch.jpg",
"events": [
"account.connected"
]
}'Headers
Idempotency-KeystringoptionalA unique key so a retried request is not applied twice. Stored for 24 hours.
Body
urlstringrequiredHTTPS endpoint that receives POSTs.
eventsenum[]requiredEvent types to subscribe to, or ["*"] for everything.
profileIdstringoptionalProfile to act on. Defaults to the profile the API key was created in.
scopeobjectoptionalDefaults to profile.
Response
Returns 201 with the following body.
WebhookSubscriptionrequired
secretstringrequiredUse this to verify the CuteDyno-Signature header.
retrySchedulenumber[]requiredRetry delays in seconds.
Example
{
"subscription": {
"id": "a1b2c3d4-0000-4000-8000-000000000000",
"url": "https://cdn.example.com/media/launch.jpg",
"events": [
"string"
],
"scope": "profile",
"isActive": false,
"createdAt": "string",
"updatedAt": "string"
},
"secret": "whsec_2f8a...",
"retrySchedule": [
0
]
}Errors
Failures use the standard error envelope. Branch on code, never on the message.
| Status | Code | When it happens |
|---|---|---|
| 400 | invalid_request | The request body or query string failed validation. The message names the offending field. |
| 401 | invalid_api_key | The key does not exist, was revoked, or is malformed. Keys start with cdyn_live_. |
| 403 | insufficient_permission | The key is missing the scope this endpoint needs, for example posts:write on a readonly key. |
| 429 | rate_limit_exceeded | Too many requests for this key. Honour the Retry-After header before retrying. |
| 500 | internal_error | Something failed on our side. Retry with the same Idempotency-Key; report the requestId if it persists. |