/api/v1/webhooks endpoints with an API key for the workspace. Both act on the same endpoints.
Managing webhooks requires the Hantera webhooks (Manage webhooks) permission in the workspace. An OAuth app needs the webhooks:write scope for every webhook and event endpoint, including the read-only ones. Endpoints that an integration such as HubSpot or Slack installed don’t appear in the API; the integration manages them.
Create an endpoint
- Dashboard
- API
- Go to Inställningar > Utvecklare > Webhooks.
- Click Skapa webhook (Create webhook).
- Fill in the form:
- Webhook URL: your endpoint. It must use HTTPS.
- Händelser (Events): the events to subscribe to.
- API-version: the version that sets the shape of the events. It defaults to your organization’s version.
- E-post vid automatisk paus (Email on automatic pause): optional; see Failure notifications.
- Hemlighet (Secret): leave it empty, and sajn generates one.
- Click Skapa webhook.
POST request to the URL. For what that request contains, see Test webhooks locally.
sajn checks the URL before it saves the endpoint. It rejects a URL that doesn’t use HTTPS, a host that resolves to a private, loopback, or link-local address, and a URL that answers a
GET request with a 2xx HTML page, which usually means that a website was entered instead of a receiver. An endpoint that isn’t deployed yet passes the check.
Store the secret
sajn returnssecret only when you create the endpoint and when you rotate it. No other response contains it. Store it when you get it; if you lose it, rotate it.
Pin the API version
Each endpoint keeps its ownapiVersion, which sets the shape of the event body and of data. The endpoint keeps it when your organization’s default version changes, so you can upgrade your API calls and your webhook receivers separately. To move an endpoint to a newer version, update your handler for the new shapes first, then set apiVersion:
2026-09 keeps its secret, which the Standard Webhooks signature uses as is. We recommend that you rotate the secret afterward, so that the endpoint gets a whsec_ secret that every Standard Webhooks library accepts. For the version lifecycle, see API versioning.
List and get endpoints
To list the workspace’s endpoints, newest first, callGET /api/v1/webhooks:
nextCursor as cursor; for more information, see Pagination. To get one endpoint, call GET /api/v1/webhooks/{id}.
An endpoint’s status is one of the following:
ENABLED: sajn delivers to it.DISABLED: you turned it off, andenabledisfalse.PAUSED: sajn paused it because it kept failing or answered410 Gone.pausedAtandpauseReasonsay when and why.
Update an endpoint
To change an endpoint, send only the fields you want to change toPATCH /api/v1/webhooks/{id}. An omitted field keeps its value. In the dashboard, select Redigera (Edit) from the endpoint’s row menu.
events replaces the whole list, so send every event that you want to keep:
url. sajn runs the same checks as on create, except that an endpoint already stored with an http:// URL can keep using HTTP. PATCH doesn’t take secret; to replace the secret, rotate it.
Turn an endpoint off
To stop deliveries without deleting the endpoint, setenabled to false:
enabled doesn’t lift a pause; reactivate the endpoint instead.
Rotate the signing secret
To replace the secret, for example after it leaked or when you lost it, callPOST /api/v1/webhooks/{id}/rotate-secret:
whsec_ secret and returns the webhook with it in secret. Store it: no other response returns it.
For 24 hours after the rotation, every delivery carries two signatures in webhook-signature, one with the new secret and one with the old one, so you can rotate without rejecting deliveries:
- Call
rotate-secretand store the new secret. - Deploy the new secret to your receiver within 24 hours. A receiver that checks every signature in the header, as the Standard Webhooks libraries do, accepts deliveries with either secret.
- After 24 hours, sajn signs with the new secret only.
An endpoint on API version
2026-09 gets one X-Sajn-Signature signature, with the current secret only, so it has no overlap. Make the receiver accept either secret before you rotate.Send a test event
To check that your endpoint receives and verifies deliveries, callPOST /api/v1/webhooks/{id}/test:
webhook.test event to this endpoint only, signed and retried like any other event, and returns the delivery with status: PENDING. data.object is the webhook’s id and url. To see the outcome, pass the delivery’s id to GET /api/v1/webhooks/{id}/deliveries/{deliveryId}. The test event doesn’t appear in GET /api/v1/events. A disabled or paused endpoint returns 409 INVALID_STATE.
Reactivate a paused endpoint
When sajn pauses an endpoint, fix the endpoint first, then reactivate it.- Dashboard
- API
- Go to Inställningar > Utvecklare > Webhooks.
- If the URL was wrong, select Redigera from the endpoint’s row menu, correct Webhook URL, and click Spara.
- In the endpoint’s Status column, click Testa och återaktivera (Test and reactivate).
2xx status code, sajn reactivates the endpoint. If it fails, the endpoint stays paused and the dashboard shows the status code. If there’s no failed delivery to test with, select Återaktivera utan test (Reactivate without testing) from the row menu instead.Delete an endpoint
To delete an endpoint, callDELETE /api/v1/webhooks/{id}, or select Ta bort (Delete) from its row menu in the dashboard:
{ "id": "cm4k2x9p10013abcd1234efgh", "deleted": true }. Deleting is permanent and also deletes the endpoint’s delivery log. Deliveries that are still queued are dropped. To stop deliveries for a while, turn the endpoint off instead.
Failure notifications
sajn notifies you when it pauses an endpoint, not on every failed delivery:- An email goes to the endpoint’s
failureNotificationEmail. If it’s empty, the email goes to the organization owner, if the owner’s notification settings allow it. - An in-app notification goes to the workspace members who can manage webhooks, and to the organization owner, if they turned on webhook failure notifications.
Use one endpoint per environment
Production and sandbox are separate organizations with separate API keys, so they have separate endpoints. Create one in each, with its own secret:SANDBOX_API_KEY with an API key from your sandbox. If both environments post to the same URL, keep a secret for each and accept a delivery that verifies with either. Then branch on the event’s environment, which is SANDBOX or PRODUCTION.
Next steps
Webhook events
Choose which events to subscribe to.
Delivery and retries
Retries, timeouts, and automatic pausing.

