Skip to main content
POST
Create a webhook endpoint

Authorizations

Authorization
string
header
required

A secret key, sk_test_... or sk_live_...; a publishable key (pk_...) on the browser routes only

Body

application/json
url
string
required

Where events are posted. https only, on a publicly reachable host.

Required string length: 1 - 2048
Example:

"https://example.com/payra/webhooks"

enabled_events
enum<string>[]
required

The event types to deliver, or * alone for every type, present and future.

Minimum array length: 1
Available options:
payment.processing,
payment.authorized,
payment.succeeded,
payment.failed,
payment.canceled,
payment.returned,
refund.pending,
refund.succeeded,
refund.failed,
checkout_session.completed,
checkout_session.expired,
*
Example:
description
string | null
Maximum string length: 500
Example:

"Order fulfilment"

Response

The endpoint, with its secret

object
enum<string>
required
Available options:
webhook_endpoint
id
string
required
Example:

"we_test_4kQ2mL7Hs1pXv4cR8tWzAbCdEf"

url
string
required
Example:

"https://example.com/payra/webhooks"

description
string | null
required
Example:

"Order fulfilment"

enabled_events
enum<string>[]
required

The event types to deliver, or * alone for every type, present and future.

Minimum array length: 1
Available options:
payment.processing,
payment.authorized,
payment.succeeded,
payment.failed,
payment.canceled,
payment.returned,
refund.pending,
refund.succeeded,
refund.failed,
checkout_session.completed,
checkout_session.expired,
*
Example:
status
enum<string>
required

A disabled endpoint keeps its configuration and secret but receives nothing.

Available options:
enabled,
disabled
Example:

"enabled"

livemode
boolean
required
Example:

false

created_at
string
required
Example:

"2026-09-19T21:04:11.000Z"

secret
string

The signing secret, present in the create response only; store it, it is never shown again.

Example:

"whsec_test_…"