> ## Documentation Index
> Fetch the complete documentation index at: https://spreecommerce.org/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a webhook endpoint

> Creates a new outbound webhook subscription. The plaintext
`secret_key` is returned **once** in this response — persist it
immediately to verify incoming webhook signatures. Subsequent reads
return `null` for the secret. Pass an empty `subscriptions` array or
omit it to receive every event.


**Required scope:** `write_webhooks` (for API-key authentication).



## OpenAPI

````yaml /api-reference/admin.yaml post /api/v3/admin/webhook_endpoints
openapi: 3.0.3
info:
  title: Admin API
  contact:
    name: Spree Commerce
    url: https://spreecommerce.org
    email: hello@spreecommerce.org
  description: >
    Spree Admin API v3 - Administrative API for managing products, orders, and
    store settings.


    ## Authentication


    The Admin API requires a secret API key passed in the `x-spree-api-key`
    header.

    Secret API keys can be generated in the Spree admin dashboard.


    ## Response Format


    All responses are JSON. List endpoints return paginated responses with
    `data` and `meta` keys.

    Single resource endpoints return a flat JSON object.


    ## Resource IDs


    Every resource is identified by an opaque string ID (e.g. `prod_86Rf07xd4z`,

    `variant_k5nR8xLq`, `or_UkLWZg9DAJ`). Use these IDs everywhere — URL paths,

    request bodies, and Ransack filters all accept them directly.


    ## Error Handling


    Errors return a consistent format:

    ```json

    {
      "error": {
        "code": "validation_error",
        "message": "Validation failed",
        "details": { "name": ["can't be blank"] }
      }
    }

    ```
  version: v3
servers:
  - url: http://{defaultHost}
    variables:
      defaultHost:
        default: localhost:3000
security: []
tags:
  - name: Authentication
    description: Admin user login, logout, token refresh, and current user profile
  - name: Allowed Origins
    description: CORS allowlist for storefront and admin client origins
  - name: API Keys
    description: Secret and publishable API keys
  - name: Channels
    description: Sales channels and product publication across channels
  - name: Custom Fields
    description: >-
      Custom field definitions for products, variants, customers, and other
      resources
  - name: Customer Groups
    description: >-
      Customer groups for segmenting customers (e.g. wholesale, VIP) used by
      pricing and promotions
  - name: Customers
    description: Customer profiles, addresses, credit cards, and store credits
  - name: Exports
    description: Async CSV exports of admin resources
  - name: Fulfillments
    description: Order fulfillments — shipments, fulfill, cancel, resume, split
  - name: Gift Cards
    description: Gift cards and gift card batches
  - name: Markets
    description: >-
      Markets — geographic groupings of countries used for pricing, tax, and
      fulfillment rules
  - name: Option Types
    description: >-
      Option types and option values used to build product variants (e.g. Size,
      Color)
  - name: Orders
    description: Orders, order items, applied gift cards, and applied store credits
  - name: Payment Methods
    description: Configured payment providers and their available types
  - name: Payments
    description: Order payments — list, capture, void
  - name: Pricing
    description: >-
      Prices and price lists for currency-, market-, and customer-group-specific
      pricing
  - name: Products
    description: >-
      Products, taxons/categories, product custom field values, and bulk product
      operations
  - name: Promotions
    description: Promotions, promotion rules, promotion actions, and coupon codes
  - name: Refunds
    description: Order refunds
  - name: Settings
    description: Store-level settings — store profile, tags, store credit categories
  - name: Staff
    description: Admin users, roles, and invitations to the store
  - name: Stock Locations
    description: Warehouses and physical fulfillment locations
  - name: Variants
    description: >-
      Product variants — the individual SKUs (size/color combinations) sold
      under a product
  - name: Webhooks
    description: Webhook endpoints and webhook delivery history
paths:
  /api/v3/admin/webhook_endpoints:
    post:
      tags:
        - Webhooks
      summary: Create a webhook endpoint
      description: |-
        Creates a new outbound webhook subscription. The plaintext
        `secret_key` is returned **once** in this response — persist it
        immediately to verify incoming webhook signatures. Subsequent reads
        return `null` for the secret. Pass an empty `subscriptions` array or
        omit it to receive every event.


        **Required scope:** `write_webhooks` (for API-key authentication).
      parameters:
        - name: x-spree-api-key
          in: header
          required: true
          schema:
            type: string
        - name: Authorization
          in: header
          required: true
          description: Bearer token for admin authentication
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              type: object
              required:
                - url
              properties:
                name:
                  type: string
                  example: Order pipeline
                url:
                  type: string
                  example: https://example.com/webhooks/orders
                active:
                  type: boolean
                  example: true
                subscriptions:
                  type: array
                  items:
                    type: string
                  example:
                    - order.completed
                    - order.canceled
      responses:
        '201':
          description: webhook endpoint created — secret_key returned once
          content:
            application/json:
              example:
                id: whe_gbHJdmfrXB
                name: CI integration
                url: https://ci.example.com/webhooks
                active: true
                subscriptions:
                  - order.completed
                disabled_reason: null
                created_at: '2026-07-11T15:38:46.198Z'
                updated_at: '2026-07-11T15:38:46.198Z'
                disabled_at: null
                secret_key: >-
                  07151923757fcbf94e634c49670951d7d555d9e05b37a34f5f28721a1286a61d
                last_delivery_at: null
                recent_delivery_count: 0
                recent_failure_count: 0
                total_delivery_count: 0
                successful_delivery_count: 0
                failed_delivery_count: 0
        '422':
          description: validation error
          content:
            application/json:
              example:
                error:
                  code: validation_error
                  message: >-
                    Url Translation missing. Options considered were:

                    -
                    en.activerecord.errors.models.spree/webhook_endpoint.attributes.url.invalid_url

                    -
                    en.activerecord.errors.models.spree/webhook_endpoint.invalid_url

                    - en.activerecord.errors.messages.invalid_url

                    - en.errors.attributes.url.invalid_url

                    - en.errors.messages.invalid_url
                  details:
                    url:
                      - >-
                        Translation missing. Options considered were:

                        -
                        en.activerecord.errors.models.spree/webhook_endpoint.attributes.url.invalid_url

                        -
                        en.activerecord.errors.models.spree/webhook_endpoint.invalid_url

                        - en.activerecord.errors.messages.invalid_url

                        - en.errors.attributes.url.invalid_url

                        - en.errors.messages.invalid_url
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - api_key: []
          bearer_auth: []
      x-codeSamples:
        - lang: javascript
          label: Spree Admin SDK
          source: >-
            import { createAdminClient } from '@spree/admin-sdk'


            const client = createAdminClient({
              baseUrl: 'https://your-store.com',
              secretKey: 'sk_xxx',
            })


            const endpoint = await client.webhookEndpoints.create({
              name: 'Order pipeline',
              url: 'https://example.com/webhooks/orders',
              active: true,
              subscriptions: ['order.completed', 'order.canceled'],
            })


            // The plaintext `secret_key` is returned exactly once on create —
            persist it

            // immediately so you can verify incoming webhook signatures.
            Subsequent reads

            // will return `null`.

            const signingSecret = endpoint.secret_key
        - lang: bash
          label: Spree CLI
          source: >-
            spree api post /webhook_endpoints -d '{"name":"Order
            pipeline","url":"https://example.com/webhooks/orders","active":true,"subscriptions":["order.completed","order.canceled"]}'
components:
  schemas:
    ErrorResponse:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              example: record_not_found
            message:
              type: string
              example: Record not found
            details:
              type: object
              description: Field-specific validation errors
              nullable: true
              example:
                name:
                  - is too short
                  - is required
                email:
                  - is invalid
          required:
            - code
            - message
      required:
        - error
      example:
        error:
          code: validation_error
          message: Validation failed
          details:
            name:
              - is too short
            email:
              - is invalid
  securitySchemes:
    api_key:
      type: apiKey
      name: x-spree-api-key
      in: header
      description: Secret API key for admin access
    bearer_auth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: JWT token for admin user authentication

````