Send a test event
/webhook-endpoints/{whep_id}/testSends one signed event of the type you choose to the endpoint straight away, with a sample object as
data.object, and returns the result of that single attempt. Use it to check your signature verification
and your response time.
- Works on disabled endpoints too, so you can check a fix before re-enabling.
- Test events aren't retried and don't appear in
GET /events.
Scope: webhooks:manage · Plan: Growth, Pro and Enterprise in live mode; every plan in test mode.
Send Authorization: Bearer <token> on every request. The token is one of:
| Prefix | What it is | Where it may be used |
|---|---|---|
agoo_sk_live_ | Secret key, live mode | Your servers only |
agoo_sk_test_ | Secret key, test mode | Your servers only |
agoo_pk_live_ | Publishable key, live mode | Browsers and apps: create pre-registrations and bookings, read public booking types (with their intake questions) and their free slots, read the visit types open for pre-registration with their public forms. Never lists people. |
agoo_pk_test_ | Publishable key, test mode | As above, in test mode |
Admins create keys in Console → Developers → API keys and choose each key's scopes. A key is shown once. Never put a secret key in a URL, a browser or a mobile app.
In: header
Scope: webhooks:manage
Path Parameters
The webhook endpoint's ID.
^whep_[0-7][0-9a-hjkmnp-tv-z]{25}$"whep_01m2jf0cg0ffyrmjbzsk9t0gtc"Header Parameters
A UUID you generate for this operation. If you retry with the same key within 24 hours, Agoo returns the
original response instead of acting twice. While the first request is still running, a retry returns
conflict. Reusing a key with a different request returns idempotency_key_reused. Responses with
rate_limited, internal_error or unavailable aren't stored, so retry those with the same key.
uuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X POST "https://example.com/webhook-endpoints/whep_01m2jf0cg0ffyrmjbzsk9t0gtc/test" \ -H "Idempotency-Key: 3f6b2a1e-8c4d-4f7a-9b2e-5d1c0a7e9f64" \ -H "Content-Type: application/json" \ -d '{ "type": "visit.checked_in" }'{ "endpoint_id": "whep_01m2jf0cg0ffyrmjbzsk9t0gtc", "event_id": "evt_01m4wwgwc0f8y8gskxtb18r86q", "type": "visit.checked_in", "attempted_at": "2026-10-14T09:40:00Z", "outcome": "succeeded", "status_code": 200, "duration_ms": 182, "error": null}Rotate an endpoint's secret POST
Creates a new signing secret, **shown only this once**. For `previous_secret_ttl_hours` (24 by default) Agoo signs every delivery with both the new and the old secret, so the `webhook-signature` header carries two signatures. Deploy the new secret, then let the old one expire. Set `previous_secret_ttl_hours` to `0` to stop using the old secret at once, for example if it leaked. **Scope:** `webhooks:manage` · **Plan:** Growth, Pro and Enterprise in live mode; every plan in test mode.
List events GET
Returns events from the last 30 days, newest first. Each event is exactly what was (or would have been) delivered to your webhook endpoints, so you can use this to catch up after downtime. **Scope:** `events:read` · **Plan:** Growth, Pro and Enterprise in live mode; every plan in test mode.