Webhooks
Update a webhook
Changes whether the webhook is enabled and/or its shared token. The URL and signing secret cannot be changed; delete the webhook and create a new one instead. Send at least one field.
- Console only: owner or admin
- Workspace:
X-Tenant-ID
Path parameters
iduuidrequiredWebhook id.
Headers
CookiestringrequiredThe
whatsappx_sessioncookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.X-Tenant-IDuuidrequiredWorkspace id. Required for session requests. You can pass
?tenant=<id>instead.
Body
application/jsonenabledbooleanoptionalTurn deliveries on or off.
tokenstringoptionalSet a new shared token (8–256 characters). An empty string removes it.
generate_tokenbooleanoptionalGenerate a new random
whtok_token.clear_tokenbooleanoptionalRemove the shared token.
Response
200 OKapplication/json
iduuidWebhook id.
urlstringHTTPS URL that receives deliveries.
eventsstringAlways
messages. It is informational and not a filter: every enabled webhook receives every event.enabledbooleanWhether deliveries are sent.
has_tokenbooleanWhether a shared token is sent in
X-Whatsappx-Webhook-Token.created_atintegerCreation time in Unix seconds.
secretstringmay be absentSigning secret (
whsec_+ 48 hex characters). Returned only in the create response; store it to verifyX-Hub-Signature-256.tokenstringmay be absentThe shared token, returned only in the response that set or generated it. Generated tokens are
whtok_+ 48 hex characters.
Status codes
- 200OK. The updated webhook.
tokenis included only when this request set or generated one;secretis never included. - 400Bad request. No change was requested (
provide enabled and/or token changes), the token is invalid, the id is invalid (invalid webhook id) or the body is not JSON (invalid body). - 401Unauthorized. No signed-in session (
unauthorized). - 403Forbidden. API keys can never call this endpoint (
API keys cannot administer workspaces). A signed-in user who is not an owner or admin getsadmin required; a user who is not a member of the workspace getsforbidden. - 404Not found. No webhook with this id in the workspace.
If you send more than one token option, clear_token wins over generate_token, which wins over token.