partner
POST /v1/partner/webhooks
Subscribe an endpoint to your customers' events.
Authentication
Send an API key as a bearer token. The key must carry the partner.domains permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/partner/webhooks \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "endpoint": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Returns the signing secret ONCE — store it before you close the response. The subscription starts unverified and receives only a signed verification POST; answer it 2xx and it becomes active. Every POST carries X-Zinn-Signature (sha256= HMAC over "<X-Zinn-Timestamp>.<raw body>"), X-Zinn-Delivery and X-Zinn-Event. Re-subscribing an endpoint you already have re-keys and re-verifies it. Requires partner.domains.
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
endpoint | string | Yes | An https:// URL we can reach from the public internet. Judged again when the socket opens, so an address that resolves to a private range is refused at delivery time as well as… |
events | string[] | No | Omit or leave empty for every event type we publish. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | string | Yes | — |
endpoint | string | Yes | — |
events | string[] | Yes | The event types this endpoint receives. An empty list means every type we publish, including ones added later. |
status | string<active, unverified, suspended> | Yes | unverified until your endpoint answers 2xx to our signed verification POST — until then it receives nothing else. suspended after 20 consecutive failures. |
verified_at | string | Yes | — |
consecutive_failures | integer | Yes | — |
last_delivery_at | string | Yes | — |
last_failure_at | string | Yes | — |
last_delivery_error | string | Yes | Why the last delivery failed, as your endpoint answered it — empty once a delivery succeeds. This is the field to read when status is suspended: the count tells you the… |
signing_secret | string | No | The HMAC key for X-Zinn-Signature. Returned ONCE, on creation, and never again — we keep only what is needed to sign. Lost it? Subscribe the same endpoint again and you get a… |
Errors this endpoint can return
401 · 403 · 422 · 429