API reference

POST/v1/webhooks

Create a webhook subscription

Registers an endpoint. Set scope to account to receive events from every profile through one endpoint. The signing secret is returned once.

Required permission: `webhooks:write`

Accepts `profileId` to target a specific profile. Omit it to use the key’s home profile.

Base URL
https://api.cutedyno.com
Permission
webhooks:write
Idempotency
Send an Idempotency-Key header so a retry cannot apply twice. How it works
MCP tool
create_webhook

Request

curl -X POST "https://api.cutedyno.com/v1/webhooks" \
  -H "Authorization: Bearer $CUTEDYNO_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "profileId": "profile_a1b2c3d4",
  "url": "https://cdn.example.com/media/launch.jpg",
  "events": [
    "account.connected"
  ]
}'

Headers

Idempotency-Keystringoptional

A unique key so a retried request is not applied twice. Stored for 24 hours.

Body

urlstringrequired

HTTPS endpoint that receives POSTs.

eventsenum[]required

Event types to subscribe to, or ["*"] for everything.

profileIdstringoptional

Profile to act on. Defaults to the profile the API key was created in.

scopeobjectoptional

Defaults to profile.

Response

Returns 201 with the following body.

WebhookSubscriptionrequired
secretstringrequired

Use this to verify the CuteDyno-Signature header.

retrySchedulenumber[]required

Retry delays in seconds.

Example

{
  "subscription": {
    "id": "a1b2c3d4-0000-4000-8000-000000000000",
    "url": "https://cdn.example.com/media/launch.jpg",
    "events": [
      "string"
    ],
    "scope": "profile",
    "isActive": false,
    "createdAt": "string",
    "updatedAt": "string"
  },
  "secret": "whsec_2f8a...",
  "retrySchedule": [
    0
  ]
}

Errors

Failures use the standard error envelope. Branch on code, never on the message.

StatusCodeWhen it happens
400invalid_requestThe request body or query string failed validation. The message names the offending field.
401invalid_api_keyThe key does not exist, was revoked, or is malformed. Keys start with cdyn_live_.
403insufficient_permissionThe key is missing the scope this endpoint needs, for example posts:write on a readonly key.
429rate_limit_exceededToo many requests for this key. Honour the Retry-After header before retrying.
500internal_errorSomething failed on our side. Retry with the same Idempotency-Key; report the requestId if it persists.