Outgoing webhooks. Every route hangs off https://api.blixye.com/v1 and carries the key in the Authorization header (see Keys and scopes). This page is generated from the API's OpenAPI specification; if it is not here, the API does not do it.
Outgoing webhooks. Every route hangs off https://api.blixye.com/v1 and carries the key in the Authorization header (see Keys and scopes). This page is generated from the API's OpenAPI specification; if it is not here, the API does not do it.
NOTE
Outgoing webhooks. Every route hangs off https://api.blixye.com/v1 and carries the key in the Authorization header (see Keys and scopes). This page is generated from the API's OpenAPI specification; if it is not here, the API does not do it.
NOTE
GET /webhooks: List webhooks (webhooks:manage)
POST /webhooks: Create a webhook (webhooks:manage)
GET /webhooks/{id}: Get a webhook (webhooks:manage)
PATCH /webhooks/{id}: Update a webhook (webhooks:manage)
DELETE /webhooks/{id}: Delete a webhook (webhooks:manage)
POST /webhooks/{id}/rotate-secret: Rotate the signing secret (webhooks:manage)
List webhooks
List webhooks
NOTE
List webhooks
GET /webhooks. The server's webhooks (never the secret). Scope: webhooks:manage.
GET /webhooks. The server's webhooks (never the secret). Scope: webhooks:manage.
NOTE
GET /webhooks. The server's webhooks (never the secret). Scope: webhooks:manage.
curl "https://api.blixye.com/v1/webhooks" \
-H "Authorization: Bearer bx_live_…"
curl "https://api.blixye.com/v1/webhooks" \
-H "Authorization: Bearer bx_live_…"
NOTE
curl "https://api.blixye.com/v1/webhooks" \
-H "Authorization: Bearer bx_live_…"
Response 200: Webhooks.
Response 200: Webhooks.
NOTE
Response 200: Webhooks.
{
"data": [
{
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "CAD to our Discord",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z"
}
]
}
{
"data": [
{
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "CAD to our Discord",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z"
}
]
}
NOTE
{
"data": [
{
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "CAD to our Discord",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z"
}
]
}
Errors (the format is in Errors):
Errors (the format is in Errors):
NOTE
Errors (the format is in Errors):
NOTE
400: Malformed request (invalid limit, cursor, JSON, Idempotency-Key, or an API key sent in the URL).
401: Missing, invalid, revoked or expired API key (codes missing_api_key, invalid_api_key, api_key_revoked, api_key_expired).
403: The key lacks a scope (missing_scope), the IP is not allowed (ip_not_allowed), the server's plan has no API (plan_required) or an MDT module is off (module_off).
429: Too many requests for this API key (the limit is per key and per minute, by plan). Too many failed authentications from one IP also give a 429.
Create a webhook
Create a webhook
NOTE
Create a webhook
POST /webhooks. Creates a webhook. The response carries the signing secret: it is the only time you will see it. Limit by plan (plus 1, premium 5, business 20). Scope: webhooks:manage.
POST /webhooks. Creates a webhook. The response carries the signing secret: it is the only time you will see it. Limit by plan (plus 1, premium 5, business 20). Scope: webhooks:manage.
NOTE
POST /webhooks. Creates a webhook. The response carries the signing secret: it is the only time you will see it. Limit by plan (plus 1, premium 5, business 20). Scope: webhooks:manage.
Parameters:
Parameters:
NOTE
Parameters:
NOTE
Idempotency-Key (header; string, optional): Makes the POST safe to retry: the same key returns the first response (with Idempotent-Replayed: true) for 24 h. The same key with a different body is a 422.
Body (JSON):
Body (JSON):
NOTE
Body (JSON):
NOTE
url (string, max 500, required): https URL. Private, loopback and reserved addresses are rejected (also after resolving DNS, and again on every delivery).
events (array, event types, required): Events to receive. An API key can only subscribe to events covered by its scopes.
description (string, max 120, nullable, optional): Description (max 120).
curl -X POST "https://api.blixye.com/v1/webhooks" \
-H "Authorization: Bearer bx_live_…" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: 5f7c1d2e-mi-reintento-1" \
-d '{"url":"https://example.com/blixye/webhook","events":["call.created"],"description":"Two suspects, one armed."}'
curl -X POST "https://api.blixye.com/v1/webhooks" \
-H "Authorization: Bearer bx_live_…" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: 5f7c1d2e-mi-reintento-1" \
-d '{"url":"https://example.com/blixye/webhook","events":["call.created"],"description":"Two suspects, one armed."}'
NOTE
curl -X POST "https://api.blixye.com/v1/webhooks" \
-H "Authorization: Bearer bx_live_…" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: 5f7c1d2e-mi-reintento-1" \
-d '{"url":"https://example.com/blixye/webhook","events":["call.created"],"description":"Two suspects, one armed."}'
Response 201: Created.
Response 201: Created.
NOTE
Response 201: Created.
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "Two suspects, one armed.",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z",
"secret": "whsec_…"
}
}
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "Two suspects, one armed.",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z",
"secret": "whsec_…"
}
}
NOTE
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "Two suspects, one armed.",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z",
"secret": "whsec_…"
}
}
Errors (the format is in Errors):
Errors (the format is in Errors):
NOTE
Errors (the format is in Errors):
NOTE
400: Malformed request (invalid limit, cursor, JSON, Idempotency-Key, or an API key sent in the URL).
401: Missing, invalid, revoked or expired API key (codes missing_api_key, invalid_api_key, api_key_revoked, api_key_expired).
403: The key lacks a scope (missing_scope), the IP is not allowed (ip_not_allowed), the server's plan has no API (plan_required) or an MDT module is off (module_off).
409: Conflict (for example, the same Idempotency-Key is still being processed, or a plan limit was reached).
422: A field is invalid (details.field says which).
429: Too many requests for this API key (the limit is per key and per minute, by plan). Too many failed authentications from one IP also give a 429.
Get a webhook
Get a webhook
NOTE
Get a webhook
GET /webhooks/{id}. One webhook. Scope: webhooks:manage.
GET /webhooks/{id}. One webhook. Scope: webhooks:manage.
NOTE
GET /webhooks/{id}. One webhook. Scope: webhooks:manage.
Parameters:
Parameters:
NOTE
Parameters:
NOTE
id (path; string, required): Resource id.
curl "https://api.blixye.com/v1/webhooks/whk_3tq0vJ1c9Ydl2Hk7WqPzEw" \
-H "Authorization: Bearer bx_live_…"
curl "https://api.blixye.com/v1/webhooks/whk_3tq0vJ1c9Ydl2Hk7WqPzEw" \
-H "Authorization: Bearer bx_live_…"
NOTE
curl "https://api.blixye.com/v1/webhooks/whk_3tq0vJ1c9Ydl2Hk7WqPzEw" \
-H "Authorization: Bearer bx_live_…"
Response 200: The webhook.
Response 200: The webhook.
NOTE
Response 200: The webhook.
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "CAD to our Discord",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z"
}
}
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "CAD to our Discord",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z"
}
}
NOTE
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "CAD to our Discord",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z"
}
}
Errors (the format is in Errors):
Errors (the format is in Errors):
NOTE
Errors (the format is in Errors):
NOTE
400: Malformed request (invalid limit, cursor, JSON, Idempotency-Key, or an API key sent in the URL).
401: Missing, invalid, revoked or expired API key (codes missing_api_key, invalid_api_key, api_key_revoked, api_key_expired).
403: The key lacks a scope (missing_scope), the IP is not allowed (ip_not_allowed), the server's plan has no API (plan_required) or an MDT module is off (module_off).
404: Not found in this server. An id from another server is always a 404.
429: Too many requests for this API key (the limit is per key and per minute, by plan). Too many failed authentications from one IP also give a 429.
Update a webhook
Update a webhook
NOTE
Update a webhook
PATCH /webhooks/{id}. Changes url, events, description or is_active. Turning a disabled webhook back on resets its failure count. Scope: webhooks:manage.
PATCH /webhooks/{id}. Changes url, events, description or is_active. Turning a disabled webhook back on resets its failure count. Scope: webhooks:manage.
NOTE
PATCH /webhooks/{id}. Changes url, events, description or is_active. Turning a disabled webhook back on resets its failure count. Scope: webhooks:manage.
Parameters:
Parameters:
NOTE
Parameters:
NOTE
id (path; string, required): Resource id.
Body (JSON):
Body (JSON):
NOTE
Body (JSON):
NOTE
url (string, max 500, optional): https URL. Private, loopback and reserved addresses are rejected (also after resolving DNS, and again on every delivery).
events (array, event types, optional): Events to receive. An API key can only subscribe to events covered by its scopes.
description (string, max 120, nullable, optional): Description (max 120).
is_active (boolean, optional): On or off.
curl -X PATCH "https://api.blixye.com/v1/webhooks/whk_3tq0vJ1c9Ydl2Hk7WqPzEw" \
-H "Authorization: Bearer bx_live_…" \
-H "Content-Type: application/json" \
-d '{"url":"https://example.com/blixye/webhook","events":["call.created"],"description":"Two suspects, one armed."}'
curl -X PATCH "https://api.blixye.com/v1/webhooks/whk_3tq0vJ1c9Ydl2Hk7WqPzEw" \
-H "Authorization: Bearer bx_live_…" \
-H "Content-Type: application/json" \
-d '{"url":"https://example.com/blixye/webhook","events":["call.created"],"description":"Two suspects, one armed."}'
NOTE
curl -X PATCH "https://api.blixye.com/v1/webhooks/whk_3tq0vJ1c9Ydl2Hk7WqPzEw" \
-H "Authorization: Bearer bx_live_…" \
-H "Content-Type: application/json" \
-d '{"url":"https://example.com/blixye/webhook","events":["call.created"],"description":"Two suspects, one armed."}'
Response 200: The webhook.
Response 200: The webhook.
NOTE
Response 200: The webhook.
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "CAD to our Discord",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z"
}
}
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "CAD to our Discord",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z"
}
}
NOTE
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "CAD to our Discord",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z"
}
}
Errors (the format is in Errors):
Errors (the format is in Errors):
NOTE
Errors (the format is in Errors):
NOTE
400: Malformed request (invalid limit, cursor, JSON, Idempotency-Key, or an API key sent in the URL).
401: Missing, invalid, revoked or expired API key (codes missing_api_key, invalid_api_key, api_key_revoked, api_key_expired).
403: The key lacks a scope (missing_scope), the IP is not allowed (ip_not_allowed), the server's plan has no API (plan_required) or an MDT module is off (module_off).
404: Not found in this server. An id from another server is always a 404.
422: A field is invalid (details.field says which).
429: Too many requests for this API key (the limit is per key and per minute, by plan). Too many failed authentications from one IP also give a 429.
Delete a webhook
Delete a webhook
NOTE
Delete a webhook
DELETE /webhooks/{id}. Deletes the webhook and its pending deliveries. Scope: webhooks:manage.
DELETE /webhooks/{id}. Deletes the webhook and its pending deliveries. Scope: webhooks:manage.
NOTE
DELETE /webhooks/{id}. Deletes the webhook and its pending deliveries. Scope: webhooks:manage.
Parameters:
Parameters:
NOTE
Parameters:
NOTE
id (path; string, required): Resource id.
curl -X DELETE "https://api.blixye.com/v1/webhooks/whk_3tq0vJ1c9Ydl2Hk7WqPzEw" \
-H "Authorization: Bearer bx_live_…"
curl -X DELETE "https://api.blixye.com/v1/webhooks/whk_3tq0vJ1c9Ydl2Hk7WqPzEw" \
-H "Authorization: Bearer bx_live_…"
NOTE
curl -X DELETE "https://api.blixye.com/v1/webhooks/whk_3tq0vJ1c9Ydl2Hk7WqPzEw" \
-H "Authorization: Bearer bx_live_…"
Response 200: Deleted.
Response 200: Deleted.
NOTE
Response 200: Deleted.
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"deleted": true
}
}
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"deleted": true
}
}
NOTE
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"deleted": true
}
}
Errors (the format is in Errors):
Errors (the format is in Errors):
NOTE
Errors (the format is in Errors):
NOTE
400: Malformed request (invalid limit, cursor, JSON, Idempotency-Key, or an API key sent in the URL).
401: Missing, invalid, revoked or expired API key (codes missing_api_key, invalid_api_key, api_key_revoked, api_key_expired).
403: The key lacks a scope (missing_scope), the IP is not allowed (ip_not_allowed), the server's plan has no API (plan_required) or an MDT module is off (module_off).
404: Not found in this server. An id from another server is always a 404.
429: Too many requests for this API key (the limit is per key and per minute, by plan). Too many failed authentications from one IP also give a 429.
Rotate the signing secret
Rotate the signing secret
NOTE
Rotate the signing secret
POST /webhooks/{id}/rotate-secret. Replaces the signing secret. The old one stops working at once; the new one is only shown in this response. Scope: webhooks:manage.
POST /webhooks/{id}/rotate-secret. Replaces the signing secret. The old one stops working at once; the new one is only shown in this response. Scope: webhooks:manage.
NOTE
POST /webhooks/{id}/rotate-secret. Replaces the signing secret. The old one stops working at once; the new one is only shown in this response. Scope: webhooks:manage.
Parameters:
Parameters:
NOTE
Parameters:
NOTE
id (path; string, required): Resource id.
curl -X POST "https://api.blixye.com/v1/webhooks/whk_3tq0vJ1c9Ydl2Hk7WqPzEw/rotate-secret" \
-H "Authorization: Bearer bx_live_…"
curl -X POST "https://api.blixye.com/v1/webhooks/whk_3tq0vJ1c9Ydl2Hk7WqPzEw/rotate-secret" \
-H "Authorization: Bearer bx_live_…"
NOTE
curl -X POST "https://api.blixye.com/v1/webhooks/whk_3tq0vJ1c9Ydl2Hk7WqPzEw/rotate-secret" \
-H "Authorization: Bearer bx_live_…"
Response 200: The webhook with its new secret.
Response 200: The webhook with its new secret.
NOTE
Response 200: The webhook with its new secret.
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "Two suspects, one armed.",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z",
"secret": "whsec_…"
}
}
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "Two suspects, one armed.",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z",
"secret": "whsec_…"
}
}
NOTE
{
"data": {
"id": "whk_3tq0vJ1c9Ydl2Hk7WqPzEw",
"url": "https://example.com/blixye/webhook",
"description": "Two suspects, one armed.",
"events": [
"call.created"
],
"is_active": true,
"secret_prefix": "whsec_Ab3d",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-27T18:04:05Z",
"last_failure_at": null,
"created_at": "2026-09-27T18:04:05Z",
"secret": "whsec_…"
}
}
Errors (the format is in Errors):
Errors (the format is in Errors):
NOTE
Errors (the format is in Errors):
NOTE
400: Malformed request (invalid limit, cursor, JSON, Idempotency-Key, or an API key sent in the URL).
401: Missing, invalid, revoked or expired API key (codes missing_api_key, invalid_api_key, api_key_revoked, api_key_expired).
403: The key lacks a scope (missing_scope), the IP is not allowed (ip_not_allowed), the server's plan has no API (plan_required) or an MDT module is off (module_off).
404: Not found in this server. An id from another server is always a 404.
429: Too many requests for this API key (the limit is per key and per minute, by plan). Too many failed authentications from one IP also give a 429.