Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview

Create a webhook subscription

Subscribe a URL to matching event types. With generateSecret, the plaintext signing secret is returned exactly once.

POST/api/v2/events/topics/{ref}/subscriptions
Authorization
AuthorizationBearer token (Anlyon API key) · headerrequired

Workspace API key sent as Authorization: Bearer <key>.

or
better-auth.session_tokenAPI key · cookierequired

Browser session used by dashboard-only operations.

Path parameters
refstringrequired

Public topic ID (top_...) or topic name. Using anlyon on create lazily creates the reserved topic.

min length 1 · max length 100
Header parameters
X-Request-Idstring

Optional caller correlation ID. Unsafe or oversized values are replaced.

max length 128
Idempotency-Keystring

Stable retry key for a mutation. The key is claimed atomically before the handler runs, so concurrent retries execute the side effect at most once. Replaying the key for the same request (same method, path, workspace and JSON body) returns the original response with an X-Idempotent-Replay: true header. Reusing the key for a different request returns 409 with error code idempotency_key_reuse. A duplicate arriving while the first is still in flight waits and then replays; if the first does not finish in time the duplicate gets 409 idempotency_request_in_progress. Keys are retained for 24 hours. Only successful (2xx) responses are stored; a failed request frees the key so it can be retried.

min length 1 · max length 255
Request body
requiredapplication/json
urlstring<uri>required
max length 2048
eventTypesEventTypePattern[]
min items 1 · max items 50 · default: ["*"]
enabledboolean
default: true
generateSecretboolean

Generate a per-subscription webhook signing secret and return it once.

default: false
headersEventHeaders
Responses
201

Subscription created. A generated plaintext secret is included only in this response.

successbooleanrequired
Allowed:true
dataEventSubscriptionCreatedrequired
Show properties
idstringrequired
matches ^sub_
urlstring<uri>required
eventTypesEventTypePattern[]required
enabledbooleanrequired
hasCustomSecretbooleanrequired
headersEventHeaders | nullrequired
Show properties
Any of:
EventHeaders
object
null
null
createdAtstring<date-time>required
updatedAtstring<date-time>required
secretstring

Plaintext signing secret, present only when generateSecret was true and never returned again.

400

Bad Request - Invalid input data

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
401

Unauthorized - Invalid or missing API key

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
402

Payment Required - Usage quota exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
403

Authenticated credential lacks the required scope or workspace access.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
404

Not Found - Resource does not exist

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
429

Too Many Requests - Rate limit exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST 'https://api.anlyon.com/api/v2/events/topics/string/subscriptions' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "url": "http://example.com",
  "eventTypes": [
    "*"
  ],
  "enabled": true,
  "generateSecret": false,
  "headers": {
    "property1": "string",
    "property2": "string"
  }
}'
Response
{
  "success": true,
  "data": {
    "id": "string",
    "url": "http://example.com",
    "eventTypes": [
      "memory.*"
    ],
    "enabled": true,
    "hasCustomSecret": true,
    "headers": {
      "property1": "string",
      "property2": "string"
    },
    "createdAt": "2019-08-24T14:15:22Z",
    "updatedAt": "2019-08-24T14:15:22Z",
    "secret": "string"
  }
}