Skip to main content
POST
Create Webhook Endpoint

Authorizations

Authorization
string
header
required

A Kite API key (kite_...), from Platform API → Keys in the dashboard.

Headers

authorization
string | null
X-Impersonation-Token
string | null
Kite-Version
enum<string>
default:2026-09-27

The dated contract your code was written against. Without it you get 2026-09-27; every response says which version served it.

Available options:
2026-09-27

Body

application/json
url
string
required
Maximum string length: 2000
enabled_events
string[] | null

Event types to receive (supports 'augmentation.*'); omit for all

Response

The endpoint, with its signing secret (shown only this once)

The endpoint just created, with its signing secret: the only time the secret is returned.

id
string
required

whk_ + a time-ordered ULID

url
string
required
status
string
required

active

secret
string
required

whsec_…: verify each delivery's Kite-Signature with it

object
enum<string>
default:webhook_endpoint
Available options:
webhook_endpoint
Allowed value: "webhook_endpoint"
enabled_events
string[] | null

The event types it receives; null means all