Create webhook endpoint
Creates a webhook endpoint and returns its whsec_… signing secret. Deliveries follow the Standard Webhooks spec (webhook-id, webhook-timestamp, webhook-signature). At most 20 endpoints per organization (422 unprocessable beyond).
bearerAuthAuthorizationBearer <token>An organization API key (koast_sk_…) with the API surface enabled, or an OAuth access token issued by Koast (koast_at_…) whose audience covers this API. REST access requires an active Agency plan.
Idempotency-Key?stringRetrying with the same key within 24 hours returns the first response without acting again.
length <= 255application/json- body
url*stringHTTPS URL Koast POSTs events to. No credentials in the URL; redirects are not followed.
1 <= length <= 2048eventTypes*array<>Event types this endpoint receives. ping is always delivered by the test send and cannot be subscribed to.
1 <= itemsbrandIds?array<>|Only deliver events of these brands. Null delivers events of every brand in the organization.
Create webhook endpoint
application/json- response
id*stringurl*stringeventTypes*array<string>brandIds*array<number>|nullstatus*stringdisabled_by_failures means Koast gave up after ~3 days of failed deliveries; enable it again once fixed.
"enabled""disabled""disabled_by_failures"disabledReason*string|nulldisabledAt*string|nullconsecutiveFailures*integer-9007199254740991 <= value <= 9007199254740991lastSuccessAt*string|nulllastFailureAt*string|nulllastError*string|nullsecretRotationExpiresAt*|While set, deliveries are signed with both the new and the previous secret.
createdAt*stringupdatedAt*stringsecret*stringThe whsec_… signing secret. Verify deliveries with any Standard Webhooks library.
curl -X POST "https://example.com/v1/webhooks" \ -H "Authorization: Bearer koast_sk_..." \ -H "Content-Type: application/json" \ -d '{ "url": "string", "eventTypes": [ "launch.completed" ] }'{ "id": "string", "url": "string", "eventTypes": [ "string" ], "brandIds": [ 0 ], "status": "enabled", "disabledReason": "string", "disabledAt": "string", "consecutiveFailures": -9007199254740991, "lastSuccessAt": "string", "lastFailureAt": "string", "lastError": "string", "secretRotationExpiresAt": "string", "createdAt": "string", "updatedAt": "string", "secret": "string"}Required scope: write. CLI: koast create-webhook-endpoint, see Webhooks commands. Authentication, headers, errors and pagination work the same on every operation. See Conventions.