Skip to content

Webhooks

List webhook endpoints

webhooks:manage
Request exampleNo request body
curl https://api.rieckflow.com/v1/webhook-endpoints \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Success envelopeapplication/json
Response fields 5
FieldTypeDescription
data.iduuidStable endpoint id.
data.urlurlHTTPS delivery destination.
data.eventTypesstring[]Subscribed event types.
data.activebooleanWhether delivery is enabled.
data.secretstringOnly returned when creating or rotating the endpoint.
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

Register endpoint

webhooks:manage

Response carries the signing secret exactly once. HTTPS only; private hosts rejected; max 10 per organisation (a hard limit in the database, not a soft one — every event costs one queue row PER endpoint). Choose payloadStyle: snapshot (default) sends the whitelisted fields as they were when the event was queued; thin sends the SAME envelope with an empty data and you fetch the object fresh. Prefer thin: less of your customers’ data leaves our systems, and you act on current state rather than on a snapshot that may be half an hour old by the time delivery succeeds.

Request body fields 4
FieldTypeRequiredDescription
urlstringYesPublic HTTPS endpoint that receives signed events.
eventTypesstring[]YesEvent types delivered to the endpoint.
descriptionstringNoHuman-readable description.
payloadStylestringNoField in the request payload.
Request exampleapplication/json
curl -X POST https://api.rieckflow.com/v1/webhook-endpoints \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041" \
-H "Content-Type: application/json" \
-d '{
"url": "https://erp.acme.example/webhooks/rieck",
"eventTypes": [
"…"
],
"description": "Consulting",
"payloadStyle": "snapshot"
}'
201 Success envelopeapplication/json
Response fields 5
FieldTypeDescription
data.iduuidStable endpoint id.
data.urlurlHTTPS delivery destination.
data.eventTypesstring[]Subscribed event types.
data.activebooleanWhether delivery is enabled.
data.secretstringOnly returned when creating or rotating the endpoint.
Possible errors 9
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
400invalid_requestThe request body or parameter failed validation.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
413payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit.
429rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"minLength": 1,
"maxLength": 500
},
"eventTypes": {
"minItems": 1,
"maxItems": 75,
"type": "array",
"items": {
"type": "string"
}
},
"description": {
"anyOf": [
{
"type": "string",
"maxLength": 200
},
{
"type": "null"
}
]
},
"payloadStyle": {
"default": "snapshot",
"type": "string",
"enum": [
"snapshot",
"thin"
]
}
},
"required": [
"url",
"eventTypes"
],
"additionalProperties": false
}

Get endpoint

webhooks:manage
ParameterInTypeRequiredDescription
endpointIdpathstringYes
Request exampleNo request body
curl https://api.rieckflow.com/v1/webhook-endpoints/9b2f1c1e-… \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Success envelopeapplication/json
Response fields 5
FieldTypeDescription
data.iduuidStable endpoint id.
data.urlurlHTTPS delivery destination.
data.eventTypesstring[]Subscribed event types.
data.activebooleanWhether delivery is enabled.
data.secretstringOnly returned when creating or rotating the endpoint.
Possible errors 5
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404webhook_endpoint_not_foundThe webhook endpoint does not exist or is inactive.
429rate_limitedThe organisation’s rate budget is exhausted.

Update endpoint

webhooks:manage

The URL cannot be changed — register a new endpoint instead. Omitting payloadStyle leaves it unchanged; it is never reset to the default, because that would start sending event data to an endpoint that deliberately opted out. A change takes effect on the NEXT delivery attempt, including for events already queued.

ParameterInTypeRequiredDescription
endpointIdpathstringYes
Request body fields 4
FieldTypeRequiredDescription
eventTypesstring[]NoEvent types delivered to the endpoint.
activebooleanNoWhether the resource is active.
descriptionstringNoHuman-readable description.
payloadStylestringNoField in the request payload.
Request exampleapplication/json
curl -X PATCH https://api.rieckflow.com/v1/webhook-endpoints/9b2f1c1e-… \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041" \
-H "Content-Type: application/json" \
-d '{
"eventTypes": [
"…"
],
"active": true,
"description": "Consulting",
"payloadStyle": "snapshot"
}'
200 Success envelopeapplication/json
Response fields 5
FieldTypeDescription
data.iduuidStable endpoint id.
data.urlurlHTTPS delivery destination.
data.eventTypesstring[]Subscribed event types.
data.activebooleanWhether delivery is enabled.
data.secretstringOnly returned when creating or rotating the endpoint.
Possible errors 10
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
400invalid_requestThe request body or parameter failed validation.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404webhook_endpoint_not_foundThe webhook endpoint does not exist or is inactive.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
413payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit.
429rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema
{
"type": "object",
"properties": {
"eventTypes": {
"minItems": 1,
"maxItems": 75,
"type": "array",
"items": {
"type": "string"
}
},
"active": {
"type": "boolean"
},
"description": {
"anyOf": [
{
"type": "string",
"maxLength": 200
},
{
"type": "null"
}
]
},
"payloadStyle": {
"type": "string",
"enum": [
"snapshot",
"thin"
]
}
},
"additionalProperties": false
}

Delete endpoint

webhooks:manage
ParameterInTypeRequiredDescription
endpointIdpathstringYes
Request exampleNo request body
curl -X DELETE https://api.rieckflow.com/v1/webhook-endpoints/9b2f1c1e-… \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041"
204 No contentNo response body
Possible errors 8
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404webhook_endpoint_not_foundThe webhook endpoint does not exist or is inactive.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
429rate_limitedThe organisation’s rate budget is exhausted.

POST /v1/webhook-endpoints/{endpointId}/rotate-secret

Section titled “POST /v1/webhook-endpoints/{endpointId}/rotate-secret”

Rotate secret (24 h overlap)

webhooks:manage
ParameterInTypeRequiredDescription
endpointIdpathstringYes
Request exampleNo request body
curl -X POST https://api.rieckflow.com/v1/webhook-endpoints/9b2f1c1e-…/rotate-secret \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041"
200 Success envelopeapplication/json
Possible errors 8
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404webhook_endpoint_not_foundThe webhook endpoint does not exist or is inactive.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
429rate_limitedThe organisation’s rate budget is exhausted.

POST /v1/webhook-endpoints/{endpointId}/test

Section titled “POST /v1/webhook-endpoints/{endpointId}/test”

Send test ping

webhooks:manage
ParameterInTypeRequiredDescription
endpointIdpathstringYes
Request exampleNo request body
curl -X POST https://api.rieckflow.com/v1/webhook-endpoints/9b2f1c1e-…/test \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041"
202 Success envelopeapplication/json
Possible errors 8
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404webhook_endpoint_not_foundThe webhook endpoint does not exist or is inactive.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
429rate_limitedThe organisation’s rate budget is exhausted.

POST /v1/webhook-endpoints/{endpointId}/replay

Section titled “POST /v1/webhook-endpoints/{endpointId}/replay”

Replay deliveries

webhooks:manage

Re-queues failed/given-up deliveries and enqueues never-queued events since since. RETENTION CONTRACT: events are kept and replayable for 90 days; since older than that is rejected (422), and so is a since in the future. At most 10,000 never-queued events are enqueued per call — call again with a later since to continue. Delivered events are never re-sent, so a replay is safe to repeat.

ParameterInTypeRequiredDescription
endpointIdpathstringYes
Request body fields 1
FieldTypeRequiredDescription
sincestringYesField in the request payload.
Request exampleapplication/json
curl -X POST https://api.rieckflow.com/v1/webhook-endpoints/9b2f1c1e-…/replay \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041" \
-H "Content-Type: application/json" \
-d '{
"since": "2026-08-15"
}'
200 Success envelopeapplication/json
Possible errors 11
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
400invalid_requestThe request body or parameter failed validation.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404webhook_endpoint_not_foundThe webhook endpoint does not exist or is inactive.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
413payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit.
422replay_window_exceededWebhook replay is limited to the last 90 days.
429rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema
{
"type": "object",
"properties": {
"since": {
"anyOf": [
{
"type": "string",
"format": "date-time",
"pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d(?::[0-5]\\d(?:\\.\\d+)?)?(?:Z|([+-](?:[01]\\d|2[0-3]):[0-5]\\d)))$"
},
{
"type": "string",
"pattern": "^\\d{4}-\\d{2}-\\d{2}$"
}
]
}
},
"required": [
"since"
],
"additionalProperties": false
}