API referenceWebhooks

Update webhook endpoint

Updates the URL, event types, brand filter or status of a webhook endpoint. Setting status to enabled also clears a disable caused by failed deliveries.

PATCH
/v1/webhooks/{endpointId}
bearerAuth
headerAuthorizationBearer <token>

An organization API key (koast_sk_…) with the API surface enabled, or an OAuth access token issued by Koast (koast_at_…) whose audience covers this API. REST access requires an active Agency plan.

endpointId*string

The webhook endpoint id (ep_…).

Length1 <= length <= 64
application/json
  1. body
url?string

HTTPS URL Koast POSTs events to. No credentials in the URL; redirects are not followed.

Length1 <= length <= 2048
eventTypes?array<>

Event types this endpoint receives. ping is always delivered by the test send and cannot be subscribed to.

Items1 <= items
brandIds?array<>|

Only deliver events of these brands. Null delivers events of every brand in the organization.

status?string

enabled also clears a disable caused by failed deliveries.

Value in"enabled""disabled"

Response Body

Update webhook endpoint

application/json
  1. response
id*string
url*string
eventTypes*array<string>
brandIds*array<number>|null
status*string

disabled_by_failures means Koast gave up after ~3 days of failed deliveries; enable it again once fixed.

Value in"enabled""disabled""disabled_by_failures"
disabledReason*string|null
disabledAt*string|null
consecutiveFailures*integer
Range-9007199254740991 <= value <= 9007199254740991
lastSuccessAt*string|null
lastFailureAt*string|null
lastError*string|null
secretRotationExpiresAt*|

While set, deliveries are signed with both the new and the previous secret.

createdAt*string
updatedAt*string
curl -X PATCH "https://example.com/v1/webhooks/string" \  -H "Authorization: Bearer koast_sk_..." \  -H "Content-Type: application/json" \  -d '{}'
{  "id": "string",  "url": "string",  "eventTypes": [    "string"  ],  "brandIds": [    0  ],  "status": "enabled",  "disabledReason": "string",  "disabledAt": "string",  "consecutiveFailures": -9007199254740991,  "lastSuccessAt": "string",  "lastFailureAt": "string",  "lastError": "string",  "secretRotationExpiresAt": "string",  "createdAt": "string",  "updatedAt": "string"}

Required scope: write. CLI: koast update-webhook-endpoint, see Webhooks commands. Authentication, headers, errors and pagination work the same on every operation. See Conventions.