partner

POST /v1/partner/webhooks

Subscribe an endpoint to your customers' events.

All partner endpoints

All developer docs →

Authentication

Send an API key as a bearer token. The key must carry the partner.domains permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/partner/webhooks \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "endpoint": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Returns the signing secret ONCE — store it before you close the response. The subscription starts unverified and receives only a signed verification POST; answer it 2xx and it becomes active. Every POST carries X-Zinn-Signature (sha256= HMAC over "<X-Zinn-Timestamp>.<raw body>"), X-Zinn-Delivery and X-Zinn-Event. Re-subscribing an endpoint you already have re-keys and re-verifies it. Requires partner.domains.

Request body

NameTypeRequiredWhat it is
endpointstringYesAn https:// URL we can reach from the public internet. Judged again when the socket opens, so an address that resolves to a private range is refused at delivery time as well as…
eventsstring[]NoOmit or leave empty for every event type we publish.

Response

NameTypeRequiredWhat it is
idstringYes—
endpointstringYes—
eventsstring[]YesThe event types this endpoint receives. An empty list means every type we publish, including ones added later.
statusstring<active, unverified, suspended>Yesunverified until your endpoint answers 2xx to our signed verification POST — until then it receives nothing else. suspended after 20 consecutive failures.
verified_atstringYes—
consecutive_failuresintegerYes—
last_delivery_atstringYes—
last_failure_atstringYes—
last_delivery_errorstringYesWhy the last delivery failed, as your endpoint answered it — empty once a delivery succeeds. This is the field to read when status is suspended: the count tells you the…
signing_secretstringNoThe HMAC key for X-Zinn-Signature. Returned ONCE, on creation, and never again — we keep only what is needed to sign. Lost it? Subscribe the same endpoint again and you get a…

Errors this endpoint can return

401 · 403 · 422 · 429