RaabtaHQ
Update a webhook endpoint

Update a webhook endpoint

PATCH/api/v1/webhooks/{id}

scope webhooks:manage

Changes the URL, the subscriptions, the description or the enabled flag; omitted fields are left alone. A new URL is validated like on create. Setting enabled: true clears an auto-disable and resets the failure count; pending deliveries resume on the next pass.

Path parameters

NameTypeDescription
idrequired
string (uuid)Webhook endpoint id

Body

application/json
NameTypeDescription
urloptional
stringHTTPS URL to POST to. See the URL rules
eventsoptional
string[]Event types to subscribe to; at least one
descriptionoptional
string | nullA note for the team
enabledoptional
booleanRe-enabling clears an auto-disable and resets the failure count
Request
curl -X PATCH "https://your-crm.example.com/api/v1/webhooks/3a4b5c6d-7e8f-4a9b-8c0d-1e2f3a4b5c6d" \
  -H "Authorization: Bearer $RAABTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "enabled": true
  }'
Response · 200 OK
{
  "data": {
    "id": "3a4b5c6d-7e8f-4a9b-8c0d-1e2f3a4b5c6d",
    "url": "https://example.com/hooks/raabta",
    "description": "Sync contacts and deals into our warehouse",
    "events": [
      "contact.created",
      "contact.updated",
      "deal.stage_changed"
    ],
    "enabled": true,
    "api_version": "2026-09-01",
    "secret_last4": "a9Fq",
    "consecutive_failures": 0,
    "disabled_at": null,
    "disabled_reason": null,
    "last_success_at": "2026-09-02T10:06:00.000Z",
    "last_error": null,
    "last_error_at": null,
    "created_at": "2026-09-01T08:00:00.000Z",
    "updated_at": "2026-09-02T10:06:00.000Z"
  }
}

Response

Wrapped in { data: … }
NameTypeDescription
idrequired
string (uuid)UUID
urlrequired
stringWhere events are POSTed
descriptionrequired
string | null
eventsrequired
string[]Subscribed event types
enabledrequired
booleanfalse = nothing is delivered; pending deliveries wait
api_versionrequired
stringThe payload version this endpoint receives
secret_last4required
stringThe last four characters of the signing secret
consecutive_failuresrequired
integerUnbroken run of failed deliveries; reset to 0 on success
disabled_atrequired
string (date-time) | null
disabled_reasonrequired
string | nullWhy it is off — `auto: …` when the platform switched it off
last_success_atrequired
string (date-time) | null
last_errorrequired
string | null
last_error_atrequired
string (date-time) | null
created_atrequired
string (date-time)ISO 8601 timestamp
updated_atrequired
string (date-time)ISO 8601 timestamp

Errors

StatusCodeWhen
400bad_requestThe request could not be parsed: malformed JSON, an invalid cursor, or a query parameter of the wrong shape.
400validation_errorThe body or query failed validation. `details` lists each failing field with a `path` and a `message`.
401unauthorizedNo usable API key: the Authorization header is missing or malformed, or the key is unknown, revoked or expired. The three are deliberately indistinguishable.
403forbiddenThe key is valid but lacks the scope this endpoint requires, or the request came from an address outside the key’s IP allowlist. The message says which.
403account_suspendedThe account this key belongs to is suspended. Rotating the key will not help; contact support.
404not_foundNo such resource in this account. A resource that exists in another account also returns this.
422unprocessableThe request was well-formed but cannot be carried out. `reason` is a stable string saying why (for example `outside_window` or `stage_not_in_pipeline`).
429rate_limitedThe per-key budget, or the per-IP budget for failed authentication, is exhausted. Honour `Retry-After` before retrying.
500internalSomething failed on our side. Safe to retry with the same Idempotency-Key; quote `request_id` if it persists.