Create a webhook subscription
Subscribe a URL to matching event types. With generateSecret, the plaintext signing secret is returned exactly once.
/api/v2/events/topics/{ref}/subscriptionsAuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
refstringrequiredPublic topic ID (top_...) or topic name. Using anlyon on create lazily creates the reserved topic.
X-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
Idempotency-KeystringStable retry key for a mutation. The key is claimed atomically before the handler runs, so concurrent retries execute the side effect at most once. Replaying the key for the same request (same method, path, workspace and JSON body) returns the original response with an X-Idempotent-Replay: true header. Reusing the key for a different request returns 409 with error code idempotency_key_reuse. A duplicate arriving while the first is still in flight waits and then replays; if the first does not finish in time the duplicate gets 409 idempotency_request_in_progress. Keys are retained for 24 hours. Only successful (2xx) responses are stored; a failed request frees the key so it can be retried.
application/jsonurlstring<uri>requiredeventTypesEventTypePattern[]enabledbooleangenerateSecretbooleanGenerate a per-subscription webhook signing secret and return it once.
headersEventHeadersSubscription created. A generated plaintext secret is included only in this response.
successbooleanrequiredtruedataEventSubscriptionCreatedrequiredShow propertiesHide properties
idstringrequiredurlstring<uri>requiredeventTypesEventTypePattern[]requiredenabledbooleanrequiredhasCustomSecretbooleanrequiredheadersEventHeaders | nullrequiredShow propertiesHide properties
objectnullcreatedAtstring<date-time>requiredupdatedAtstring<date-time>requiredsecretstringPlaintext signing secret, present only when generateSecret was true and never returned again.
Bad Request - Invalid input data
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectUnauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectPayment Required - Usage quota exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectAuthenticated credential lacks the required scope or workspace access.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectNot Found - Resource does not exist
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectToo Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
