> ## Documentation Index
> Fetch the complete documentation index at: https://docs.payra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a webhook endpoint

> Registers a URL to receive signed events. Up to 16 per workspace and environment. The response carries the signing `secret` once.



## OpenAPI

````yaml /api-reference/openapi-v1.json post /webhook-endpoints
openapi: 3.1.0
info:
  title: Payra API
  version: v1
  description: >-
    The Payra API. Authenticate with a secret key: `Authorization: Bearer
    sk_test_...`. The two payment method session endpoints Payra Elements calls
    also take a publishable key with the session's `client_secret`.
servers:
  - url: https://api-dashboard.payra.com/v1
    description: 'Sandbox and live: the key decides which'
security: []
paths:
  /webhook-endpoints:
    post:
      tags:
        - Webhooks
      summary: Create a webhook endpoint
      description: >-
        Registers a URL to receive signed events. Up to 16 per workspace and
        environment. The response carries the signing `secret` once.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                url:
                  type: string
                  minLength: 1
                  maxLength: 2048
                  example: https://example.com/payra/webhooks
                  description: >-
                    Where events are posted. `https` only, on a publicly
                    reachable host.
                enabled_events:
                  type: array
                  items:
                    type: string
                    enum:
                      - payment.processing
                      - payment.authorized
                      - payment.succeeded
                      - payment.failed
                      - payment.canceled
                      - payment.returned
                      - refund.pending
                      - refund.succeeded
                      - refund.failed
                      - checkout_session.completed
                      - checkout_session.expired
                      - '*'
                  minItems: 1
                  example:
                    - payment.succeeded
                    - payment.failed
                  description: >-
                    The event types to deliver, or `*` alone for every type,
                    present and future.
                description:
                  type:
                    - string
                    - 'null'
                  maxLength: 500
                  example: Order fulfilment
              required:
                - url
                - enabled_events
      responses:
        '201':
          description: The endpoint, with its secret
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebhookEndpoint'
        '400':
          description: >-
            Validation error, a URL that cannot be delivered to, or the endpoint
            limit reached
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing, invalid or revoked API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: The API is not enabled for the workspace, or the key lacks the scope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limit exceeded; see Retry-After
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearerAuth: []
components:
  schemas:
    WebhookEndpoint:
      type: object
      properties:
        object:
          type: string
          enum:
            - webhook_endpoint
        id:
          type: string
          example: we_test_4kQ2mL7Hs1pXv4cR8tWzAbCdEf
        url:
          type: string
          example: https://example.com/payra/webhooks
        description:
          type:
            - string
            - 'null'
          example: Order fulfilment
        enabled_events:
          type: array
          items:
            type: string
            enum:
              - payment.processing
              - payment.authorized
              - payment.succeeded
              - payment.failed
              - payment.canceled
              - payment.returned
              - refund.pending
              - refund.succeeded
              - refund.failed
              - checkout_session.completed
              - checkout_session.expired
              - '*'
          minItems: 1
          example:
            - payment.succeeded
            - payment.failed
          description: >-
            The event types to deliver, or `*` alone for every type, present and
            future.
        status:
          type: string
          enum:
            - enabled
            - disabled
          example: enabled
          description: >-
            A disabled endpoint keeps its configuration and secret but receives
            nothing.
        secret:
          type: string
          example: whsec_test_…
          description: >-
            The signing secret, present in the create response only; store it,
            it is never shown again.
        livemode:
          type: boolean
          example: false
        created_at:
          type: string
          example: '2026-09-19T21:04:11.000Z'
      required:
        - object
        - id
        - url
        - description
        - enabled_events
        - status
        - livemode
        - created_at
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - invalid_request_error
                - authentication_error
                - permission_error
                - rate_limit_error
                - idempotency_error
                - card_error
                - api_error
            code:
              type: string
            message:
              type: string
            param:
              type: string
            request_id:
              type: string
          required:
            - type
            - code
            - message
            - request_id
          additionalProperties:
            type: string
      required:
        - error
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        A secret key, `sk_test_...` or `sk_live_...`; a publishable key
        (`pk_...`) on the browser routes only

````