Update webhook

Updates a webhook endpoint. Only the fields you send change.

Authentication

AuthorizationBearer
Bearer token. Use `ss_live_…` for live data or `ss_test_…` for the sandbox (test mode). See [Authentication](https://docs.spreadspace.app/api/authentication).

Path parameters

idstringRequiredformat: "uuid"
The webhook endpoint's id.

Headers

Idempotency-KeystringOptional<=255 characters
Idempotency token. Retries that reuse the key within 24h replay the original response. Up to 255 characters; a UUID is typical. See [Idempotency](https://docs.spreadspace.app/api/idempotency).
SpreadSpace-VersionstringOptionalformat: "^\d{4}-\d{2}-\d{2}$"
Pin the API version, e.g. `2026-07-19`. Omit to get the latest. See [Versioning](https://docs.spreadspace.app/api/versioning).

Request

This endpoint expects an object.
descriptionstring or nullOptional
statusstring or nullOptional

Status update. Null = unchanged. Only "active" or "paused" are accepted; "revoked" is reached exclusively via DELETE.

subscribed_eventslist of enums or nullOptional

Response headers

X-Request-IDstringOptional
Correlation ID for this request. Quote it in support tickets.
Idempotency-Replayboolean

Set to true when the response is replayed from the idempotency cache for a request that re-presented an Idempotency-Key it had already used. Absent on the original (winner) response. Replays are byte-for-byte identical to the original response body.

SpreadSpace-VersionstringOptional

The API surface version the server resolved for this request. Always present, regardless of whether the client supplied the request-side SpreadSpace-Version header. Default: 2026-07-19.

RateLimit-Limitinteger
Request budget of the endpoint's rate-limit policy per 60-second sliding window. See [Rate limits](https://docs.spreadspace.app/api/rate-limits).
RateLimit-Remaininginteger

Requests left in the current window. Suppressed on 429 responses produced outside the rate limiter (for example a usage throttle), where a remaining budget would be misleading.

RateLimit-Resetinteger

Seconds until a guaranteed-fresh window.

RateLimit-PolicystringOptional

The active policy in limit;w=window-seconds form.

Response

OK
idstringformat: "uuid"
urlstring
statusstring
subscribed_eventslist of enums
created_atdatetime
descriptionstring or nullOptional
signing_secret_prefixstring or nullOptional

First few characters of the active signing secret (e.g. whsec_abc1), enough to tell two secrets apart without exposing either. Null when the endpoint has no current signing secret.

revoked_atdatetime or nullOptional

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
409
Conflict Error
429
Too Many Requests Error
500
Internal Server Error