Webhooksv4

Create a webhook

POST/webhooks

Subscribes an HTTPS endpoint to events. Returns the signing secret once, on creation.

Headers

AuthorizationRequiredstring

Your API key, sent as a bearer token: Authorization: Bearer <api_key>. Editing this stays in sync with the API key box on the right.

Bearer

Body parameters

JSON
urlRequiredstring

HTTPS endpoint.

event_typesoptionalstring[]

Retired. Every webhook receives every event; filter by type in your handler. Omit this field, or send ["*"]. Any narrower value is rejected with 422 event_types_retired. Subscriptions created before the retirement keep the list they were registered with.

api_keyoptionalstring

Scope the subscription to the lines this API key owns. Omit api_key and integration_id for an organization-wide subscription that receives events from every line. Must belong to your organization; sending both is rejected with 422 ambiguous_scope.

integration_idoptionalstring

Scope the subscription to the lines this integration owns. Mutually exclusive with api_key.

channel_idoptionalstring
channel_typeoptionalstring
"blooio""twilio""whatsapp""whatsapp_business""rcs_business"

Returns

dataoptionalWebhookWithSecret
idoptionalstring

Webhook id (wh_...).

urloptionalstring
event_typesoptionalstring[]

The events this webhook receives. ["*"] for every webhook created since event filtering was retired; subscriptions registered before that keep their original list, which is frozen and cannot be changed.

statusoptionalstring
"active""disabled"
scopeoptionalstring

Which lines this subscription receives events for. organization covers every line; the other two are limited to the lines that owner holds.

"organization""api_key""integration"
api_keyoptionalstring | null

The owning API key when scope is api_key, otherwise null.

integration_idoptionalstring | null

The owning integration when scope is integration, otherwise null.

channel_idoptionalstring | null
channel_typeoptionalstring | null
created_atoptionalinteger
signing_secretoptionalstring

Returned once, on creation. Store it to verify signatures.

Response codes

201Created webhook (includes signing_secret once)
400The request was malformed — check the path, query parameters, and body.
401Your API key is missing or invalid. Pass it as a bearer token.
422Validation failed — one or more fields in the request are invalid or missing.

Sends a live request with your values and shows the real response below. Your key is stored only in this browser.

Request
curl -X POST https://api.blooio.com/v4/webhooks \
Body object
Response objectexample
{  "data": {    "id": "wh_a1b2c3d4",    "url": "https://example.com",    "event_types": [      "string"    ],    "status": "active",    "scope": "organization",    "api_key": "sk_live_a1b2c3d4",    "integration_id": "wh_a1b2c3d4",    "channel_id": "ch_a1b2c3d4",    "channel_type": "string",    "created_at": 0,    "signing_secret": "sk_live_a1b2c3d4"  }}