> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lobbystack.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a webhook endpoint

> Subscribes a URL to events. The response includes the signing secret once.



## OpenAPI

````yaml /api-reference/openapi.json post /webhooks
openapi: 3.1.0
info:
  title: LobbyStack API
  version: v1
  description: >-
    Read calls, contacts, appointments and messages, book appointments, and
    subscribe to webhooks. Authenticate with an API key in the Authorization
    header. Each key allows 120 requests per minute by default.
servers:
  - url: https://app.lobbystack.com/api/v1
security:
  - bearerAuth: []
tags:
  - name: Business
  - name: Calls
  - name: Contacts
  - name: Appointments
  - name: Messages
  - name: Knowledge
  - name: Webhooks
paths:
  /webhooks:
    post:
      tags:
        - Webhooks
      summary: Create a webhook endpoint
      description: >-
        Subscribes a URL to events. The response includes the signing secret
        once.
      operationId: createWebhook
      parameters:
        - name: Idempotency-Key
          in: header
          description: >-
            A unique value, up to 255 characters, that makes retries of this
            request safe for 24 hours.
          schema:
            type: string
            maxLength: 255
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WebhookEndpointCreate'
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                type: object
                required:
                  - data
                properties:
                  data:
                    $ref: '#/components/schemas/WebhookEndpointWithSecret'
        '400':
          description: The request is invalid (invalid_request).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: The API key is missing, invalid, or revoked (unauthorized).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: The API key lacks the webhooks:manage scope (insufficient_scope).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: The request conflicts with the current state.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: >-
            Too many requests (rate_limited). Wait for the Retry-After header's
            number of seconds.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          headers:
            Retry-After:
              schema:
                type: integer
              description: Seconds to wait.
      security:
        - bearerAuth: []
components:
  schemas:
    WebhookEndpointCreate:
      type: object
      properties:
        url:
          description: HTTPS URL that receives events.
          type: string
          maxLength: 2000
          format: uri
        events:
          minItems: 1
          type: array
          items:
            type: string
            enum:
              - call.completed
              - appointment.booked
              - appointment.rescheduled
              - appointment.cancelled
              - message.taken
              - contact.created
        description:
          type: string
          maxLength: 200
      required:
        - url
        - events
      additionalProperties: false
    WebhookEndpointWithSecret:
      type: object
      properties:
        id:
          description: Stable identifier (UUID).
          type: string
          format: uuid
        url:
          type: string
        description:
          anyOf:
            - type: string
            - type: 'null'
        events:
          type: array
          items:
            type: string
            enum:
              - call.completed
              - appointment.booked
              - appointment.rescheduled
              - appointment.cancelled
              - message.taken
              - contact.created
        status:
          type: string
          enum:
            - enabled
            - disabled
        disabled_reason:
          anyOf:
            - type: string
              enum:
                - manual
                - failing
            - type: 'null'
        created_at:
          description: ISO 8601 timestamp in UTC.
          type: string
          format: date-time
        updated_at:
          description: ISO 8601 timestamp in UTC.
          type: string
          format: date-time
        secret:
          description: >-
            Signing secret (whsec_...). Returned only when the endpoint is
            created.
          type: string
      required:
        - id
        - url
        - description
        - events
        - status
        - disabled_reason
        - created_at
        - updated_at
        - secret
      additionalProperties: false
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - invalid_request
                - unauthorized
                - forbidden
                - insufficient_scope
                - not_found
                - conflict
                - idempotency_key_reused
                - idempotency_request_in_progress
                - booking_disabled
                - booking_requires_confirmation
                - slot_unavailable
                - rate_limited
                - rate_limit_unavailable
                - method_not_allowed
                - internal_error
            message:
              type: string
            details:
              type: array
              items:
                type: object
                properties:
                  path:
                    type: string
                  message:
                    type: string
                required:
                  - path
                  - message
                additionalProperties: false
          required:
            - code
            - message
          additionalProperties: false
      required:
        - error
      additionalProperties: false
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        An API key from Settings > API keys. Scopes: business:read,
        business:write, calls:read, contacts:read, contacts:write,
        appointments:read, appointments:write, messages:read, knowledge:write,
        webhooks:manage.

````