Request example No request body
curl https://api.rieckflow.com/v1/webhook-endpoints \
-H " Authorization: Bearer $RIECK_API_KEY "
const svar = await rieck . request ( " GET " , " /v1/webhook-endpoints " );
"id" : " 9b2f1c1e-6b87-4d9b-91a0-47c8d72b8440 " ,
"url" : " https://erp.acme.example/webhooks/rieck " ,
"description" : " Production events " ,
"previousSecretExpiresAt" : null ,
"createdAt" : " 2026-08-04T09:32:11Z "
200 Success envelope application/json
Response fields 5
Field Type Description data.iduuidStable endpoint id. data.urlurlHTTPS delivery destination. data.eventTypesstring[]Subscribed event types. data.activebooleanWhether delivery is enabled. data.secretstringOnly returned when creating or rotating the endpoint.
Possible errors 4
HTTP Code Meaning 401 invalid_api_keyThe API key is missing, invalid, expired or revoked. 403 api_not_includedThe organisation’s plan does not include API access. 403 insufficient_scopeThe key does not have the required scope. 429 rate_limitedThe organisation’s rate budget is exhausted.
Response carries the signing secret exactly once. HTTPS only; private hosts rejected; max 10 per organisation (a hard limit in the database, not a soft one — every event costs one queue row PER endpoint). Choose payloadStyle: snapshot (default) sends the whitelisted fields as they were when the event was queued; thin sends the SAME envelope with an empty data and you fetch the object fresh. Prefer thin: less of your customers’ data leaves our systems, and you act on current state rather than on a snapshot that may be half an hour old by the time delivery succeeds.
Request body fields 4
Field Type Required Description urlstringYes Public HTTPS endpoint that receives signed events. eventTypesstring[]Yes Event types delivered to the endpoint. descriptionstringNo Human-readable description. payloadStylestringNo Field in the request payload.
Request example application/json
curl -X POST https://api.rieckflow.com/v1/webhook-endpoints \
-H " Authorization: Bearer $RIECK_API_KEY " \
-H " Idempotency-Key: order-2041 " \
-H " Content-Type: application/json " \
"url": "https://erp.acme.example/webhooks/rieck",
"description": "Consulting",
"payloadStyle": "snapshot"
const svar = await rieck . request ( " POST " , " /v1/webhook-endpoints " , {
" url " : " https://erp.acme.example/webhooks/rieck " ,
" description " : " Consulting " ,
" payloadStyle " : " snapshot "
"id" : " 9b2f1c1e-6b87-4d9b-91a0-47c8d72b8440 " ,
"url" : " https://erp.acme.example/webhooks/rieck " ,
"description" : " Production events " ,
"previousSecretExpiresAt" : null ,
"createdAt" : " 2026-08-04T09:32:11Z " ,
"secret" : " whsec_7a4db0f80d2c4c74 "
201 Success envelope application/json
Response fields 5
Field Type Description data.iduuidStable endpoint id. data.urlurlHTTPS delivery destination. data.eventTypesstring[]Subscribed event types. data.activebooleanWhether delivery is enabled. data.secretstringOnly returned when creating or rotating the endpoint.
Possible errors 9
HTTP Code Meaning 400 invalid_idempotency_keyIdempotency-Key is missing or malformed. 400 invalid_requestThe request body or parameter failed validation. 401 invalid_api_keyThe API key is missing, invalid, expired or revoked. 403 api_not_includedThe organisation’s plan does not include API access. 403 insufficient_scopeThe key does not have the required scope. 409 idempotency_conflictThe same key was used with a different request. 409 idempotency_in_progressThe same operation is currently being processed. Retry later. 413 payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit. 429 rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema "additionalProperties" : false
Parameter In Type Required Description endpointIdpath stringYes
Request example No request body
curl https://api.rieckflow.com/v1/webhook-endpoints/9b2f1c1e-… \
-H " Authorization: Bearer $RIECK_API_KEY "
const svar = await rieck . request ( " GET " , " /v1/webhook-endpoints/9b2f1c1e-… " );
"id" : " 9b2f1c1e-6b87-4d9b-91a0-47c8d72b8440 " ,
"url" : " https://erp.acme.example/webhooks/rieck " ,
"description" : " Production events " ,
"previousSecretExpiresAt" : null ,
"createdAt" : " 2026-08-04T09:32:11Z "
200 Success envelope application/json
Response fields 5
Field Type Description data.iduuidStable endpoint id. data.urlurlHTTPS delivery destination. data.eventTypesstring[]Subscribed event types. data.activebooleanWhether delivery is enabled. data.secretstringOnly returned when creating or rotating the endpoint.
Possible errors 5
HTTP Code Meaning 401 invalid_api_keyThe API key is missing, invalid, expired or revoked. 403 api_not_includedThe organisation’s plan does not include API access. 403 insufficient_scopeThe key does not have the required scope. 404 webhook_endpoint_not_foundThe webhook endpoint does not exist or is inactive. 429 rate_limitedThe organisation’s rate budget is exhausted.
The URL cannot be changed — register a new endpoint instead. Omitting payloadStyle leaves it unchanged; it is never reset to the default, because that would start sending event data to an endpoint that deliberately opted out. A change takes effect on the NEXT delivery attempt, including for events already queued.
Parameter In Type Required Description endpointIdpath stringYes
Request body fields 4
Field Type Required Description eventTypesstring[]No Event types delivered to the endpoint. activebooleanNo Whether the resource is active. descriptionstringNo Human-readable description. payloadStylestringNo Field in the request payload.
Request example application/json
curl -X PATCH https://api.rieckflow.com/v1/webhook-endpoints/9b2f1c1e-… \
-H " Authorization: Bearer $RIECK_API_KEY " \
-H " Idempotency-Key: order-2041 " \
-H " Content-Type: application/json " \
"description": "Consulting",
"payloadStyle": "snapshot"
const svar = await rieck . request ( " PATCH " , " /v1/webhook-endpoints/9b2f1c1e-… " , {
" description " : " Consulting " ,
" payloadStyle " : " snapshot "
"id" : " 9b2f1c1e-6b87-4d9b-91a0-47c8d72b8440 " ,
"url" : " https://erp.acme.example/webhooks/rieck " ,
"description" : " Production events " ,
"previousSecretExpiresAt" : null ,
"createdAt" : " 2026-08-04T09:32:11Z "
200 Success envelope application/json
Response fields 5
Field Type Description data.iduuidStable endpoint id. data.urlurlHTTPS delivery destination. data.eventTypesstring[]Subscribed event types. data.activebooleanWhether delivery is enabled. data.secretstringOnly returned when creating or rotating the endpoint.
Possible errors 10
HTTP Code Meaning 400 invalid_idempotency_keyIdempotency-Key is missing or malformed. 400 invalid_requestThe request body or parameter failed validation. 401 invalid_api_keyThe API key is missing, invalid, expired or revoked. 403 api_not_includedThe organisation’s plan does not include API access. 403 insufficient_scopeThe key does not have the required scope. 404 webhook_endpoint_not_foundThe webhook endpoint does not exist or is inactive. 409 idempotency_conflictThe same key was used with a different request. 409 idempotency_in_progressThe same operation is currently being processed. Retry later. 413 payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit. 429 rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema "additionalProperties" : false
Parameter In Type Required Description endpointIdpath stringYes
Request example No request body
curl -X DELETE https://api.rieckflow.com/v1/webhook-endpoints/9b2f1c1e-… \
-H " Authorization: Bearer $RIECK_API_KEY " \
-H " Idempotency-Key: order-2041 "
const svar = await rieck . request ( " DELETE " , " /v1/webhook-endpoints/9b2f1c1e-… " );
204 No content No response body
Possible errors 8
HTTP Code Meaning 400 invalid_idempotency_keyIdempotency-Key is missing or malformed. 401 invalid_api_keyThe API key is missing, invalid, expired or revoked. 403 api_not_includedThe organisation’s plan does not include API access. 403 insufficient_scopeThe key does not have the required scope. 404 webhook_endpoint_not_foundThe webhook endpoint does not exist or is inactive. 409 idempotency_conflictThe same key was used with a different request. 409 idempotency_in_progressThe same operation is currently being processed. Retry later. 429 rate_limitedThe organisation’s rate budget is exhausted.
Parameter In Type Required Description endpointIdpath stringYes
Request example No request body
curl -X POST https://api.rieckflow.com/v1/webhook-endpoints/9b2f1c1e-…/rotate-secret \
-H " Authorization: Bearer $RIECK_API_KEY " \
-H " Idempotency-Key: order-2041 "
const svar = await rieck . request ( " POST " , " /v1/webhook-endpoints/9b2f1c1e-…/rotate-secret " );
"secret" : " whsec_7a4db0f80d2c4c74 " ,
"previousSecretValidFor" : " 24h "
200 Success envelope application/json
Possible errors 8
HTTP Code Meaning 400 invalid_idempotency_keyIdempotency-Key is missing or malformed. 401 invalid_api_keyThe API key is missing, invalid, expired or revoked. 403 api_not_includedThe organisation’s plan does not include API access. 403 insufficient_scopeThe key does not have the required scope. 404 webhook_endpoint_not_foundThe webhook endpoint does not exist or is inactive. 409 idempotency_conflictThe same key was used with a different request. 409 idempotency_in_progressThe same operation is currently being processed. Retry later. 429 rate_limitedThe organisation’s rate budget is exhausted.
Parameter In Type Required Description endpointIdpath stringYes
Request example No request body
curl -X POST https://api.rieckflow.com/v1/webhook-endpoints/9b2f1c1e-…/test \
-H " Authorization: Bearer $RIECK_API_KEY " \
-H " Idempotency-Key: order-2041 "
const svar = await rieck . request ( " POST " , " /v1/webhook-endpoints/9b2f1c1e-…/test " );
202 Success envelope application/json
Possible errors 8
HTTP Code Meaning 400 invalid_idempotency_keyIdempotency-Key is missing or malformed. 401 invalid_api_keyThe API key is missing, invalid, expired or revoked. 403 api_not_includedThe organisation’s plan does not include API access. 403 insufficient_scopeThe key does not have the required scope. 404 webhook_endpoint_not_foundThe webhook endpoint does not exist or is inactive. 409 idempotency_conflictThe same key was used with a different request. 409 idempotency_in_progressThe same operation is currently being processed. Retry later. 429 rate_limitedThe organisation’s rate budget is exhausted.
Re-queues failed/given-up deliveries and enqueues never-queued events since since. RETENTION CONTRACT: events are kept and replayable for 90 days; since older than that is rejected (422), and so is a since in the future. At most 10,000 never-queued events are enqueued per call — call again with a later since to continue. Delivered events are never re-sent, so a replay is safe to repeat.
Parameter In Type Required Description endpointIdpath stringYes
Request body fields 1
Field Type Required Description sincestringYes Field in the request payload.
Request example application/json
curl -X POST https://api.rieckflow.com/v1/webhook-endpoints/9b2f1c1e-…/replay \
-H " Authorization: Bearer $RIECK_API_KEY " \
-H " Idempotency-Key: order-2041 " \
-H " Content-Type: application/json " \
const svar = await rieck . request ( " POST " , " /v1/webhook-endpoints/9b2f1c1e-…/replay " , {
200 Success envelope application/json
Possible errors 11
HTTP Code Meaning 400 invalid_idempotency_keyIdempotency-Key is missing or malformed. 400 invalid_requestThe request body or parameter failed validation. 401 invalid_api_keyThe API key is missing, invalid, expired or revoked. 403 api_not_includedThe organisation’s plan does not include API access. 403 insufficient_scopeThe key does not have the required scope. 404 webhook_endpoint_not_foundThe webhook endpoint does not exist or is inactive. 409 idempotency_conflictThe same key was used with a different request. 409 idempotency_in_progressThe same operation is currently being processed. Retry later. 413 payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit. 422 replay_window_exceededWebhook replay is limited to the last 90 days. 429 rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema "pattern" : " ^(?:(?: \\ d \\ d[2468][048]| \\ d \\ d[13579][26]| \\ d \\ d0[48]|[02468][048]00|[13579][26]00)-02-29| \\ d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12] \\ d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12] \\ d|30)|(?:02)-(?:0[1-9]|1 \\ d|2[0-8])))T(?:(?:[01] \\ d|2[0-3]):[0-5] \\ d(?::[0-5] \\ d(?: \\ . \\ d+)?)?(?:Z|([+-](?:[01] \\ d|2[0-3]):[0-5] \\ d)))$ "
"pattern" : " ^ \\ d{4}- \\ d{2}- \\ d{2}$ "
"additionalProperties" : false