Get a webhook endpoint
/webhook-endpoints/{whep_id}Returns one webhook endpoint, without its secret. Check status and disabled_reason to see whether
Agoo has disabled it after repeated failures.
Scope: webhooks:manage · Plan: Growth, Pro and Enterprise in live mode; every plan in test mode.
Send Authorization: Bearer <token> on every request. The token is one of:
| Prefix | What it is | Where it may be used |
|---|---|---|
agoo_sk_live_ | Secret key, live mode | Your servers only |
agoo_sk_test_ | Secret key, test mode | Your servers only |
agoo_pk_live_ | Publishable key, live mode | Browsers and apps: create pre-registrations and bookings, read public booking types (with their intake questions) and their free slots, read the visit types open for pre-registration with their public forms. Never lists people. |
agoo_pk_test_ | Publishable key, test mode | As above, in test mode |
Admins create keys in Console → Developers → API keys and choose each key's scopes. A key is shown once. Never put a secret key in a URL, a browser or a mobile app.
In: header
Scope: webhooks:manage
Path Parameters
The webhook endpoint's ID.
^whep_[0-7][0-9a-hjkmnp-tv-z]{25}$"whep_01m2jf0cg0ffyrmjbzsk9t0gtc"Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/webhook-endpoints/whep_01m2jf0cg0ffyrmjbzsk9t0gtc"{ "id": "whep_01m2jf0cg0ffyrmjbzsk9t0gtc", "url": "https://hooks.voltabank.example/agoo", "description": "Front desk integration", "enabled_events": [ "visit.checked_in", "visit.checked_out", "delivery.received" ], "status": "enabled", "disabled_reason": null, "created_at": "2026-09-15T12:00:00Z", "updated_at": "2026-09-15T12:00:00Z"}Create a webhook endpoint POST
Registers a URL to receive events. The response includes the endpoint's signing `secret`, **shown only this once**. Store it with your other secrets and use it to verify every delivery. - `url` must be a public HTTPS address, without a user name or password. Its host must resolve, and only to public addresses: Agoo checks when you save it and again before every delivery. Agoo doesn't follow redirects. - List the event types you want in `enabled_events`, or `["*"]` for every type, including types added later, except `watchlist.matched`, which an endpoint receives only by listing it. - An endpoint created with a test key receives test-mode events (`livemode: false`) only. **Scope:** `webhooks:manage` · **Plan:** Growth, Pro and Enterprise in live mode; every plan in test mode.
Update a webhook endpoint PATCH
Changes an endpoint's URL, description or event types, or disables and re-enables it. Send only the fields you want to change. Setting `status` to `enabled` on an endpoint that Agoo disabled after repeated failures turns deliveries back on for new events. **Scope:** `webhooks:manage` · **Plan:** Growth, Pro and Enterprise in live mode; every plan in test mode.