Skip to content

API

Using API requires at least Plus Plan

API keys are the primary way to authenticate programmatic access to Webhookah. Use the interactive workbench when you are debugging a single callback by hand. Use the HTTP API when you want automation—scripts, CI, or your own services—against the same product surface.

This guide covers creating a key and three calls you will use often: create an endpoint, read the requests that arrived, and throw the endpoint away when the test is done. Live routes, request shapes, and response schemas are documented in the OpenAPI reference.

  1. Sign in to your account (or sign up if you are new).
  2. Open Dashboard → API Key.
  3. Click Create API Key.
  4. Give the key a short description so you can recognize it later.
  5. Copy the key once and store it somewhere safe. You will not be able to read the full secret again.
  6. Call the API with the key. Prefer:
Authorization: Bearer <api_key>
  1. Confirm the call in your client (and in the workbench when the operation affects endpoints or requests you can inspect).

Calls in this section use https://api.webhookah.com and the key from Dashboard → API Key. Receive URLs stay on https://webhookah.com/wh/….

Terminal window
export WEBHOOKAH_API_KEY="wh-your-key"

Send Authorization: Bearer $WEBHOOKAH_API_KEY on /api/... routes. Hand the public receive URL (/wh/{token}) to the system that sends the webhook.

POST /api/endpoints takes no body and returns 201 with the public URL and the token for later calls.

Terminal window
curl -sS -X POST "https://api.webhookah.com/api/endpoints" \
-H "Authorization: Bearer $WEBHOOKAH_API_KEY"
{
"id": 42,
"url": "https://webhookah.com/wh/alpha-artemis-5aa3d2fc",
"token": "alpha-artemis-5aa3d2fc",
"createdAt": "2026-10-03T12:00:00Z"
}

Give url to the system that will send the webhook. Keep token for listing and deleting. A 403 with {"error":"URL limit reached for your plan"} means the account is at its endpoint limit.

GET /api/requests/endpoint/{token} returns the requests captured by one endpoint. GET /api/requests returns every request on the account.

Terminal window
curl -sS "https://api.webhookah.com/api/requests/endpoint/alpha-artemis-5aa3d2fc" \
-H "Authorization: Bearer $WEBHOOKAH_API_KEY"
[
{
"id": 1001,
"endpointId": 42,
"method": "POST",
"headers": {
"Content-Type": "application/json",
"User-Agent": "curl/8.7.1"
},
"body": {
"raw": "{\"event\":\"order.paid\",\"id\":\"ord_123\"}",
"json": {
"event": "order.paid",
"id": "ord_123"
}
},
"queryParams": {},
"ipAddress": "203.0.113.10",
"receivedAt": "2026-10-03T12:01:00Z"
}
]

No traffic yet returns []. When the sender used Content-Type: application/json and the body is a JSON object, body.json is the parsed object and body.raw is the original text.

To watch requests as they arrive, open GET /api/sse with the same Authorization header. The response is text/event-stream: requests already stored are sent first, then each new request, plus a heartbeat about every 30 seconds.

Terminal window
curl -N "https://api.webhookah.com/api/sse" \
-H "Authorization: Bearer $WEBHOOKAH_API_KEY"

Each event is one data: line. A captured request looks like this (body here is the raw text):

data: {"SSEWebhookRequest":{"id":1001,"endpointId":42,"method":"POST","headers":{"Content-Type":"application/json"},"body":"{\"event\":\"order.paid\",\"id\":\"ord_123\"}","queryParams":{},"ipAddress":"203.0.113.10","receivedAt":"2026-10-03T12:01:00Z"}}

A heartbeat looks like this:

data: {"SSEHeartbeat":{"timestamp":"2026-10-03T12:01:30Z"}}

Create an endpoint, send one callback, read what arrived, delete that endpoint’s requests, then delete the endpoint. This script uses jq to read url and token from the create response.

Terminal window
CREATE=$(curl -sS -X POST "https://api.webhookah.com/api/endpoints" \
-H "Authorization: Bearer $WEBHOOKAH_API_KEY")
URL=$(printf '%s' "$CREATE" | jq -r .url)
TOKEN=$(printf '%s' "$CREATE" | jq -r .token)
printf 'Send webhooks to %s\n' "$URL"
curl -sS -X POST "$URL" \
-H "Content-Type: application/json" \
-d '{"event":"order.paid","id":"ord_123"}'
curl -sS "https://api.webhookah.com/api/requests/endpoint/$TOKEN" \
-H "Authorization: Bearer $WEBHOOKAH_API_KEY"
curl -sS -o /dev/null -w "cleared requests: %{http_code}\n" \
-X DELETE "https://api.webhookah.com/api/requests/endpoint/$TOKEN" \
-H "Authorization: Bearer $WEBHOOKAH_API_KEY"
curl -sS -o /dev/null -w "deleted endpoint: %{http_code}\n" \
-X DELETE "https://api.webhookah.com/api/endpoints/$TOKEN" \
-H "Authorization: Bearer $WEBHOOKAH_API_KEY"

The sample send prints {"id":1001,"message":"Webhook received successfully"}. Clearing requests and deleting the endpoint both return 204. Clear the requests while the endpoint still exists. Deleting the endpoint also removes any requests still stored for it, and that URL stops accepting traffic.

The same calls are in a Postman collection. Download it and import it to run them from Postman. Install steps are on the Postman collection page.

Do not guess path names from memory. Open the full interactive reference:

OpenAPI reference →

That page is the Redocly build of the product OpenAPI document. Use it for methods, paths, parameters, and schemas.