agency-board

POST /v1/agency/boards/{boardId}/webhooks

Add an outbound webhook.

All agency-board endpoints

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/agency/boards/{boardId}/webhooks \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string>, "url": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

HTTPS only. We mint the signing secret and return it **once, in this response**. There is no endpoint that can read it back, so keep it — rotate to get a new one. Deliveries are signed `X-Zinn-Signature: sha256=<hmac over "<timestamp>.<body>">` with `X-Zinn-Timestamp`, `X-Zinn-Delivery` and `X-Zinn-Event` beside them. The timestamp is bound INTO the signature so a captured request cannot be replayed for ever, and so a receiver cannot be tricked about which timestamp it was.

Parameters

NameTypeRequiredWhat it is
boardId (path)UuidYesProject board ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
namestringYes
urlstringYesHTTPS only. Private and link-local addresses are refused when the socket opens, not when you save.
eventsstring[]NoEmpty means every event this board emits.
statusstring<enabled, disabled>No

Response

NameTypeRequiredWhat it is
idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
board_idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringYes
urlstringYes
eventsstring[]No
statusBoardAutomationStatusYes`suspended` means WE paused it after repeated failure and it carries a reason the customer has not read. It is a third state rather than a reuse of `disabled`, because collapsin…
has_secretbooleanYesWhether a signing secret is stored. The secret itself is in Vault and is returned only by create and rotate; no endpoint can read it back.
consecutive_failuresintegerNo
suspended_reasonstringNoWhy we paused this webhook, in authored copy from a closed table — never an exception from our own code. It distinguishes your endpoint refusing a delivery, your endpoint being…
suspended_atstringNo
last_delivered_atstringNo
last_failed_atstringNo
created_atstringNo
secretstringYesShown ONCE, here. Store it now; rotate to get a new one.

Errors this endpoint can return

401 · 403 · 404 · 422