https://api.veriko.mx/v1/webhooks/{id}Update a webhook endpoint
How-to guide →Updates the receiving address, the subscribed events, or the status of an already registered endpoint. Only what arrives in the body changes: an absent field stays as it was, and a body with no editable field responds 422 no_valid_fields. The signing secret does not change here. Changing the address leaves the same secret on the new endpoint, so a receiver that already validated signatures keeps validating them. To rotate it there is POST /v1/webhooks/{id}/regenerate-secret. Setting the status to disabled stops deliveries without losing the history; that is the move while a downed receiver is being fixed, rather than deleting the endpoint and creating it again.
| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
id* | path | string (uuid) | required | UUID of the webhook endpoint. e.g.f47ac10b-58cc-4372-a567-0e02b2c3d479 |
| Parameter | Type | Required | Description |
|---|---|---|---|
url | string (uri) (?–2048) | optional | HTTPS destination URL. Replaces the previous URL when provided. e.g.https://example.com/webhooks/entregas |
events | array<string> (items: 1–10) | optional | Webhook event subscription. Replaces the previous list; max 10 events. |
description | string | nullnullable (?–255) | optional | Free-form webhook label ( Alta de pagos en el ERP |
status | string (enum) | optional | Changes the webhook state ( active |
curl -X PUT 'https://api.veriko.mx/v1/webhooks/{id}' \
-H 'Authorization: Bearer veriko_••••' \
-H 'Content-Type: application/json' \
-d '{
"url": "https://webhook.example.com/platform",
"events": [
"validation.completed"
],
"status": "active"
}'Python example — coming soon.
JavaScript example — coming soon.
PHP example — coming soon.
| Field | Type | Description |
|---|---|---|
type* | string | Resource type, fixed for this operation. Part of the resource identity in the JSON:API envelope. Always webhook_endpoint |
id* | string (uuid) | Endpoint identifier. e.g.a1b2c3d4-e5f6-7890-abcd-ef0123456789 |
attributes* | object | Canonical webhook endpoint attributes (receiver URL, subscribed events, status, and secret). |
url | string (uri) | HTTPS receiver URL. Production rejects plain HTTP, URLs resolving to private IPs (SSRF), and URLs https://example.com/webhooks/entregas |
events | array | List of subscribed events. Maximum 10. |
description | string | nullnullable | Free-form endpoint label. e.g.Alta de pagos en el ERP |
status | string |
active |
consecutive_failures | integer | Consecutive failures counter. Resets on a success. e.g.0 |
last_delivery_at | TimestampUTC | null | UTC timestamp of the last delivery attempt (any status). |
secret | string | Shared secret for signature verification. Only present in the create and rotate-secret responses; omitted from every other response. e.g.whsec_a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 |
secret_hint | string | Last 4 chars of the secret prefixed with ...4f2a |
created_at | string (date-time) | ISO 8601 timestamp in UTC with explicit 2026-05-01T05:14:38Z |
updated_at | string (date-time) | ISO 8601 timestamp in UTC with explicit 2026-05-01T05:14:38Z |
| Status | Class | Description | Body |
|---|---|---|---|
| 200 | 2xx | Endpoint updated. | No body |
| 400 | 4xx | The request body is empty or is not valid JSON. | ErrorResponse |
| 401 | 4xx | Authentication is required or the provided credentials are invalid. | ErrorResponse |
| 403 | 4xx | Insufficient permissions. | ErrorResponse |
| 404 | 4xx | not_found — endpoint does not exist or does not belong to the user. | ErrorResponse |
| 413 | 4xx | The request body exceeds the maximum accepted size (body_too_large). | ErrorResponse |
| 422 | 4xx | Invalid data. Possible codes: webhook_url_empty, webhook_url_too_long, webhook_url_invalid_format, webhook_url_not_https, webhook_events_required, webhook_events_too_many, webhook_event_invalid, webhook_status_invalid, no_valid_fields. | ErrorResponse |
| 429 | 4xx | Rate limit exceeded | ErrorResponse |
| Status | Code | Example |
|---|---|---|
| 400 | body_empty | The request body is empty. Envelope
|
| 400 | invalid_json | The body is not valid JSON. Envelope
|
| 401 | unauthorized | Invalid or missing authentication credentials. Envelope
|
| 403 | forbidden | You do not have permission to access this resource. Envelope
|
| 413 | body_too_large | The request body is too large. Envelope
|
| 429 | rate_limit_exceeded | Rate limit exceeded. Try again in 45 seconds. Envelope
Response headers
|