Skip to main content

Register an endpoint

Needs the webhooks:manage scope. You can also register endpoints in Settings → Webhooks.
Response
The signing secret is returned only once, in this response. If you lose it, delete the endpoint and create a new one.
string
required
Where to send events. It must:
  • use https://
  • resolve to a public address. Private, loopback, link-local, carrier-grade NAT, multicast and IPv6 ranges that embed an IPv4 address (NAT64, 6to4, Teredo) are refused.
  • not contain a username or password
A URL that breaks these rules returns 422. The address is checked again at every delivery.
string[]
The events to receive. Leave it out to receive every event, including ones added later.
To list endpoints, call GET /webhook-endpoints. To remove one, call DELETE /webhook-endpoints/{id}. You can’t edit an endpoint, so delete it and create a new one.

Events

Payload

  • id is the event id. It’s the same for every endpoint that receives the event.
  • data.object is the invoice as it was when the event happened, in the same shape as GET /invoices. It has no lines. Call GET /invoices/{id} for those.
Each request carries webhook-id, webhook-timestamp and webhook-signature headers. Verify them before you trust the payload.
Webhooks are currently delivered once a day, at 03:00 UTC. An event can take up to 24 hours to arrive. For anything time-sensitive, poll GET /invoices or GET /invoices/{id}/events.