API reference

Webhooks

Create a webhook subscription

Registers an endpoint. Set scope to account to receive events from every profile through one endpoint. The signing secret is returned once.

Required permission: `webhooks:write`

Accepts `profileId` to target a specific profile. Omit it to use the key’s home profile.

POST/v1/webhookswebhooks:write

Request

Authorization

Send your API key as a Bearer token in the Authorization header.

Headers

Idempotency-Keystringoptional

A unique key so a retried request is not applied twice. Stored for 24 hours.

Request body

urlstringrequired

HTTPS endpoint that receives POSTs.

eventsenum[]required

Event types to subscribe to, or ["*"] for everything.

profileIdstringoptional

Profile to act on. Defaults to the profile the API key was created in.

scopeobjectoptional

Defaults to profile.

Response

Returns 201.

WebhookSubscriptionrequired
secretstringrequired

Use this to verify the CuteDyno-Signature header.

retrySchedulenumber[]required

Retry delays in seconds.

Errors

Failures use the standard error format.

StatusCodeWhen it happens
400invalid_requestThe request body or query string failed validation. The message names the offending field.
401invalid_api_keyThe key does not exist, was revoked, or is malformed. Keys start with cdyn_live_.
403insufficient_permissionThe key is missing the scope this endpoint needs, for example posts:write on a readonly key.
429rate_limit_exceededToo many requests for this key. Honour the Retry-After header before retrying.
500internal_errorSomething failed on our side. Retry with the same Idempotency-Key; report the requestId if it persists.