Skip to main content
POST
Register a webhook endpoint

Authorizations

Authorization
string
header
required

Dashboard JWT token from Clerk

Headers

Idempotency-Key
string

Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the Idempotency-Replay: true response header.

Required string length: 1 - 255
X-Test-Mode
enum<string>

Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.

Available options:
true,
false

Body

application/json
url
string<uri>
required

HTTPS endpoint URL.

Example:

"https://yourapp.com/webhooks/orbit"

events
string[]
required

Subscribed event types (e.g. message.delivered, call.completed, verification.approved). Pass ["*"] to subscribe to every event type, including ones added later.

Minimum array length: 1
Example:
secret
string

Optional shared secret. Used to verify the X-Devotel-Signature HMAC on every delivery.

Minimum string length: 16
active
boolean
default:true

Whether to start dispatching events immediately.

description
string
Maximum string length: 255
timeout_seconds
integer
default:30

Per-endpoint HTTP delivery timeout in seconds (1-30). The dispatcher aborts an in-flight delivery once this many seconds elapse. Defaults to 30 (the platform hard ceiling) when omitted.

Required range: 1 <= x <= 30
headers
object

Optional per-endpoint custom request headers (e.g. {"Authorization": "Bearer …", "X-API-Key": "…"}) sent on every delivery so you can authenticate to gateways/middleware that require header-based auth. Up to 20 headers. Orbit-managed headers (Content-Type, the X-Devotel-/X-Orbit- signature + identity headers, Idempotency-Key, User-Agent) cannot be overridden and are rejected.

retry_policy
object
transform
object

Response

Endpoint registered

Endpoint registered

data
object
meta
object