Skip to main content
POST
Create a webhook subscription

Authorizations

DPoP
string
header
required

Per-request RFC 9449 DPoP proof signed with ES256. Protected requests use Authorization: DPoP your_access_token_here. Create a new proof for the exact method and normalized target URI, and include the server nonce when challenged.

Authorization
string
header
required

OAuth 2.0 with RFC 9700 security practices. Discover exact environment endpoints from /.well-known/openid-configuration and /.well-known/oauth-authorization-server, and discover the resource from /.well-known/oauth-protected-resource. Authorization-code clients use PKCE S256, the exact environment resource, nonce with openid, and DPoP binding. Confidential clients also require PAR and private_key_jwt. Access and refresh tokens are sender-constrained with DPoP. purchases:execute is unavailable and omitted from this scope registry.

Headers

X-Request-Id
string

Optional caller request identifier. Unsafe values are replaced with a generated UUID.

Pattern: ^[A-Za-z0-9._~-]{8,128}$
Idempotency-Key
string
required

A new 256-bit random value encoded as 43 unpadded base64url characters. Reuse it only for the same request intent.

Pattern: ^[A-Za-z0-9_-]{43}$

Body

application/json

A request to create an operation webhook subscription.

url
string<uri>
required

HTTPS callback URL to validate and subscribe.

Maximum string length: 2048

Response

The new subscription and signing secret, including exact equal replay.

A newly created subscription and signing secret, or the same exact idempotency replay.

id
string<uuid>
required

API-owned webhook-subscription identifier.

Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
url
string<uri>
required

Normalized HTTPS callback URL.

Maximum string length: 2048
created_at
string<date-time>
required

Time the subscription became active.

Pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
kid
string<uuid>
required

Identifier of the initial signing-secret version.

Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
secret
string
required

Base64url-encoded 256-bit signing secret disclosed initially and on exact idempotency replay.

Pattern: ^[A-Za-z0-9_-]{43}$