Webhooks
POST/v1/webhooks/endpoints
Add an endpoint — the signing secret comes back once and never again
Store the signingSecret before you do anything else with the response. It is the only thing that tells a delivery of ours apart from any other POST to your public endpoint, and we cannot show it to you a second time.
- Auth
- API key
- Scope
- webhooks:manage
- Rate limit
- DEFAULT
- Search quota
- Free
- Idempotency
- Idempotency-Key
Request headers
Request body
CreateWebhookEndpointDto — required, sent as application/json.
Responses
Errors
Every one of these carries the same envelope. What each error.type means, and whether a retry can succeed, is on the error index — once, for all operations.
Response headers
Set on every response of this operation, successful or not.
Example
curl -sS -X POST "$VACABEE_API_URL/v1/webhooks/endpoints" \
-H "Authorization: Bearer $VACABEE_API_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{
"url": "https://api.example.com/hooks/vacabee",
"events": [
"booking.confirmed",
"payment.refunded"
]
}'Set VACABEE_API_URL to https://api.vacabee.com with a live key, or to https://sandbox-api.vacabee.com with a vcb_test_ key. Binding a host to one kind of key is planned and is not enforced by the host yet, so nothing stops a key from being answered at the wrong base URL — assert the prefix against your configured URL yourself. What the sandbox answers
TypeScript SDK
await vacabee.webhooks.create(…);The typed method sends the right headers, derives the idempotency key where one is required, and returns the response type generated from this document. Installing and using the SDK

