Update a webhook endpoint
PATCH/api/v1/webhooks/{id}
scope
webhooks:manageChanges the URL, the subscriptions, the description or the enabled flag; omitted fields are left alone. A new URL is validated like on create. Setting enabled: true clears an auto-disable and resets the failure count; pending deliveries resume on the next pass.
Path parameters
| Name | Type | Description |
|---|---|---|
idrequired | string (uuid) | Webhook endpoint id |
Body
application/json| Name | Type | Description |
|---|---|---|
urloptional | string | HTTPS URL to POST to. See the URL rules |
eventsoptional | string[] | Event types to subscribe to; at least one |
descriptionoptional | string | null | A note for the team |
enabledoptional | boolean | Re-enabling clears an auto-disable and resets the failure count |
Request
curl -X PATCH "https://your-crm.example.com/api/v1/webhooks/3a4b5c6d-7e8f-4a9b-8c0d-1e2f3a4b5c6d" \
-H "Authorization: Bearer $RAABTA_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"enabled": true
}'Response · 200 OK
{
"data": {
"id": "3a4b5c6d-7e8f-4a9b-8c0d-1e2f3a4b5c6d",
"url": "https://example.com/hooks/raabta",
"description": "Sync contacts and deals into our warehouse",
"events": [
"contact.created",
"contact.updated",
"deal.stage_changed"
],
"enabled": true,
"api_version": "2026-09-01",
"secret_last4": "a9Fq",
"consecutive_failures": 0,
"disabled_at": null,
"disabled_reason": null,
"last_success_at": "2026-09-02T10:06:00.000Z",
"last_error": null,
"last_error_at": null,
"created_at": "2026-09-01T08:00:00.000Z",
"updated_at": "2026-09-02T10:06:00.000Z"
}
}Response
Wrapped in { data: … }| Name | Type | Description |
|---|---|---|
idrequired | string (uuid) | UUID |
urlrequired | string | Where events are POSTed |
descriptionrequired | string | null | |
eventsrequired | string[] | Subscribed event types |
enabledrequired | boolean | false = nothing is delivered; pending deliveries wait |
api_versionrequired | string | The payload version this endpoint receives |
secret_last4required | string | The last four characters of the signing secret |
consecutive_failuresrequired | integer | Unbroken run of failed deliveries; reset to 0 on success |
disabled_atrequired | string (date-time) | null | |
disabled_reasonrequired | string | null | Why it is off — `auto: …` when the platform switched it off |
last_success_atrequired | string (date-time) | null | |
last_errorrequired | string | null | |
last_error_atrequired | string (date-time) | null | |
created_atrequired | string (date-time) | ISO 8601 timestamp |
updated_atrequired | string (date-time) | ISO 8601 timestamp |
Errors
| Status | Code | When |
|---|---|---|
| 400 | bad_request | The request could not be parsed: malformed JSON, an invalid cursor, or a query parameter of the wrong shape. |
| 400 | validation_error | The body or query failed validation. `details` lists each failing field with a `path` and a `message`. |
| 401 | unauthorized | No usable API key: the Authorization header is missing or malformed, or the key is unknown, revoked or expired. The three are deliberately indistinguishable. |
| 403 | forbidden | The key is valid but lacks the scope this endpoint requires, or the request came from an address outside the key’s IP allowlist. The message says which. |
| 403 | account_suspended | The account this key belongs to is suspended. Rotating the key will not help; contact support. |
| 404 | not_found | No such resource in this account. A resource that exists in another account also returns this. |
| 422 | unprocessable | The request was well-formed but cannot be carried out. `reason` is a stable string saying why (for example `outside_window` or `stage_not_in_pipeline`). |
| 429 | rate_limited | The per-key budget, or the per-IP budget for failed authentication, is exhausted. Honour `Retry-After` before retrying. |
| 500 | internal | Something failed on our side. Safe to retry with the same Idempotency-Key; quote `request_id` if it persists. |