Skip to content

Register a webhook endpoint

POST
/v1/webhooks
curl --request POST \
--url https://api.roundrobinbot.eu/v1/webhooks \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json-patch+json' \
--data '{ "name": "example", "url": "example", "eventTypes": [ "example" ] }'

Registers a destination for every rotation in the workspace and answers with the signing secret, once: nothing returns it again, and a caller who loses it rotates rather than recovering it. The URL is judged before anything is stored: not https, or resolving into a private, loopback, link-local or cloud-metadata range, is a 400 with a code saying which. Credentials embedded in it are removed, and the endpoint in the response carries the URL we will actually dial. No precondition header. There is no prior version to match, and unlike a rotation a duplicate registration is visible in a list of at most ten rows and deleted in one call, so an Idempotency-Key would buy a retry nothing it cannot already see.

One of:
null
Examplegenerated
{
"name": "example",
"url": "example",
"eventTypes": [
"example"
]
}

Created

Media typeapplication/json

A newly registered endpoint, and one of the two moments its signing secret exists outside your hands.

object
endpoint

A registered destination: where Round Robin posts this workspace’s events, what it is subscribed to, and whether we are still calling it. Never the signing secret.

object
id
string
name

What the receiving system is called. Shown in the dashboard, never used for lookup.

string
url

Where we post. Always https.

string
eventTypes

What this endpoint receives: duty.changed, nobody.on_call, rotation.created, rotation.updated, rotation.deleted.

Array<string>
state

enabled or disabled. There is no revoked state: delete the endpoint instead.

string
disabledReason

Why we stopped calling: manual, delivery_failures or plan_downgrade. Absent while the endpoint is enabled.

null | string
currentSecretId

Which secret is signing now, so your logs and ours name the same one.

null | string
currentSecretCreatedAt
null | string format: date-time
previousSecretId

The outgoing secret during a rotation’s grace window, absent at every other time.

null | string
previousSecretExpiresAt

When the outgoing secret stops signing. Until then both signatures travel in one header, so a receiver can cut over without an outage.

null | string format: date-time
createdAt

When the endpoint was registered.

string format: date-time
updatedAt
null | string format: date-time
signingSecret

Sign-verification secret, returned exactly once.

string
Examplegenerated
{
"endpoint": {
"id": "example",
"name": "example",
"url": "example",
"eventTypes": [
"example"
],
"state": "example",
"disabledReason": "example",
"currentSecretId": "example",
"currentSecretCreatedAt": "2026-04-15T12:00:00Z",
"previousSecretId": "example",
"previousSecretExpiresAt": "2026-04-15T12:00:00Z",
"createdAt": "2026-04-15T12:00:00Z",
"updatedAt": "2026-04-15T12:00:00Z"
},
"signingSecret": "example"
}

Bad Request

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

Unauthorized

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

Payment Required

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

Forbidden

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

Not Found

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

Conflict

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}