Create a webhook endpoint
/v1/webhook_endpointsSubscribe a URL to one or more signal types. Requires the webhook_endpoints:write scope, which is opt-in — a key does not receive it unless it is asked for explicitly.
Every signal_types entry must be permitted by this endpoint’s scopes — a type whose required scope is missing is refused with a 400 naming that scope, never accepted and silently undelivered.
An endpoint can never hold a scope your API key does not hold. Otherwise a narrow key could mint a wide endpoint and read, through the webhook, what its own scopes forbid.
The url must be https, carry no credentials, use the default port, and not resolve to a private or internal address. The signing secret is returned once in this response and never again — store it now and use it to verify the svix-signature header on every delivery (the Standard Webhooks webhook-signature alias carries the same value and is accepted by the official libraries, but is not the name we send).
Authorization
bearerAuth Your club API key. Send it as Authorization: Bearer oc_live_….
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://api.getopencourt.com/v1/webhook_endpoints" \ -H "Content-Type: application/json" \ -d '{ "url": "https://hooks.example.com/opencourt", "scopes": [ "customers:read" ], "signal_types": [ "customer.created", "customer.updated" ] }'{
"id": "8f1b2c3d-4e5f-4a6b-9c7d-0e1f2a3b4c5d",
"object": "webhook_endpoint",
"url": "https://hooks.example.com/opencourt",
"scopes": [
"customers:read"
],
"signal_types": [
"customer.created",
"customer.updated"
],
"status": "active",
"disabled_reason": null,
"created_at": "2026-08-28T14:30:00.000Z",
"secret": "whsec_R2FsYWN0aWNGZWRlcmF0aW9u"
}{
"error": {
"type": "string",
"code": "string",
"message": "string",
"param": "string",
"request_id": "string"
}
}{
"error": {
"type": "string",
"code": "string",
"message": "string",
"param": "string",
"request_id": "string"
}
}{
"error": {
"type": "string",
"code": "string",
"message": "string",
"param": "string",
"request_id": "string"
}
}