> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trypost.it/llms.txt
> Use this file to discover all available pages before exploring further.

# Create webhook

> Creates an enabled webhook that sends the chosen post events to your endpoint. The response includes the `signing_secret`. The endpoint must be a public `http` or `https` URL: other schemes and private or local addresses are refused with `422` `This endpoint is not allowed.` on `endpoint`.

Each delivery is a JSON `POST` with the body `{id, type, data, created_at}` and the header `X-Webhook-Signature`: the hex HMAC-SHA256 of the raw body, keyed with the webhook's `signing_secret`. Compare it with your own HMAC of the body before trusting it. A delivery that does not get a 2xx answer within 10 seconds is retried twice, a minute apart. Redirects are not followed.



## OpenAPI

````yaml /openapi.json post /webhooks
openapi: 3.1.0
info:
  title: TryPost API
  version: 2.0.0
  description: >-
    REST API for TryPost. Authenticate with a workspace API key as a Bearer
    token.
servers:
  - url: https://app.trypost.it/api
    description: TryPost Cloud
security:
  - bearerAuth: []
tags:
  - name: Posts
    description: Create, read, update, delete and preview posts.
  - name: Post notes
    description: Internal notes on a post, visible to workspace members.
  - name: Approvals
    description: Approve or reject posts waiting for approval.
  - name: Recurrence
    description: Make a post repeat on a schedule.
  - name: Media and uploads
    description: Upload files and attach media to posts.
  - name: Social accounts
    description: Connected social accounts and their network-specific options.
  - name: Channels
    description: A channel's posting schedule and queue.
  - name: Ideas
    description: Ideas on the Create board.
  - name: Idea stages
    description: The groups (columns) of the ideas board.
  - name: Analytics
    description: Workspace and channel insights.
  - name: Labels
    description: Labels to organize posts and ideas.
  - name: Signatures
    description: Reusable text to append to posts.
  - name: Workspace
    description: The workspace the API key belongs to.
  - name: API keys
    description: Personal API keys for this workspace.
  - name: Webhooks
    description: Outgoing webhooks and their delivery logs.
  - name: Repurposes
    description: Automations that republish videos posted outside TryPost.
  - name: Platform
    description: Platform capabilities and content types.
paths:
  /webhooks:
    post:
      tags:
        - Webhooks
      summary: Create webhook
      description: >-
        Creates an enabled webhook that sends the chosen post events to your
        endpoint. The response includes the `signing_secret`. The endpoint must
        be a public `http` or `https` URL: other schemes and private or local
        addresses are refused with `422` `This endpoint is not allowed.` on
        `endpoint`.


        Each delivery is a JSON `POST` with the body `{id, type, data,
        created_at}` and the header `X-Webhook-Signature`: the hex HMAC-SHA256
        of the raw body, keyed with the webhook's `signing_secret`. Compare it
        with your own HMAC of the body before trusting it. A delivery that does
        not get a 2xx answer within 10 seconds is retried twice, a minute apart.
        Redirects are not followed.
      operationId: createWebhook
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - endpoint
                - events
              properties:
                endpoint:
                  type: string
                  format: uri
                  maxLength: 255
                events:
                  type: array
                  minItems: 1
                  items:
                    $ref: '#/components/schemas/WebhookEventType'
            example:
              endpoint: https://example.com/hooks/trypost
              events:
                - post.published
                - post.failed
      responses:
        '201':
          description: The created webhook, with its signing secret.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Webhook'
              example:
                id: 9b2c3d4e-5f6a-4b7c-8d9e-0f1a2b3c4d5e
                endpoint: https://example.com/hooks/trypost
                events:
                  - post.published
                  - post.failed
                status: enabled
                last_sent_at: null
                paused_at: null
                consecutive_failures: 0
                created_at: '2026-09-15T10:00:00+00:00'
                updated_at: '2026-10-08T14:00:03+00:00'
                signing_secret: whsec_4qXbV8kP2mT7nR1sW9yZ3cE6hJ0aL5dF
        '401':
          $ref: '#/components/responses/Unauthorized'
        '402':
          $ref: '#/components/responses/PaymentRequired'
        '403':
          $ref: '#/components/responses/Forbidden'
        '422':
          $ref: '#/components/responses/ValidationError'
        '429':
          $ref: '#/components/responses/TooManyRequests'
components:
  schemas:
    WebhookEventType:
      type: string
      enum:
        - post.created
        - post.scheduled
        - post.unscheduled
        - post.published
        - post.partially_published
        - post.failed
        - post.deleted
      description: >-
        - `post.created`: a post was created. Its `data.status` is the status it
        was created with (`draft`, `scheduled`, `publishing` or
        `pending_approval`).

        - `post.scheduled`: an existing post was scheduled (for example a draft
        scheduled, or a request approved). A post created already scheduled
        sends only `post.created`.

        - `post.unscheduled`: a scheduled post went back to draft or to pending
        approval.

        - `post.published`: every destination was published.

        - `post.partially_published`: some destinations were published and
        others failed.

        - `post.failed`: publishing failed.

        - `post.deleted`: a post was deleted. Not sent for posts imported from
        the network or removed by disconnecting their channel. Its `data` is
        only `{id, workspace_id}`.
    Webhook:
      type: object
      properties:
        id:
          type: string
          format: uuid
        endpoint:
          type: string
          format: uri
        events:
          type: array
          items:
            $ref: '#/components/schemas/WebhookEventType'
        status:
          type: string
          enum:
            - enabled
            - disabled
            - paused
          description: >-
            `paused` is set by TryPost after 5 failed deliveries in a row (the
            account owner is emailed). Set `status: enabled` to resume.
        last_sent_at:
          type:
            - string
            - 'null'
          format: date-time
          description: ISO 8601, UTC.
          examples:
            - '2026-10-08T14:00:03+00:00'
        paused_at:
          type:
            - string
            - 'null'
          format: date-time
          description: ISO 8601, UTC.
        consecutive_failures:
          type: integer
        signing_secret:
          type: string
          description: >-
            Secret used to sign deliveries (`whsec_` and 32 characters). Only
            returned when you create, get or rotate the webhook.
          examples:
            - whsec_4qXbV8kP2mT7nR1sW9yZ3cE6hJ0aL5dF
        created_at:
          type: string
          format: date-time
          description: ISO 8601, UTC.
          examples:
            - '2026-09-15T10:00:00+00:00'
        updated_at:
          type: string
          format: date-time
          description: ISO 8601, UTC.
          examples:
            - '2026-10-08T14:00:03+00:00'
    ErrorBody:
      type: object
      properties:
        message:
          type: string
    ValidationErrorBody:
      type: object
      properties:
        message:
          type: string
        errors:
          type: object
          additionalProperties:
            type: array
            items:
              type: string
    RateLimitErrorBody:
      type: object
      properties:
        name:
          type: string
          const: rate_limit_exceeded
        message:
          type: string
          examples:
            - Rate limit exceeded. Please retry after 30 seconds.
  responses:
    Unauthorized:
      description: >-
        Missing, invalid, revoked or expired API key. Bodies: `Unauthenticated.`
        (no key, or a key that is invalid or revoked), `Token expired.` (past
        its `expires_at`), `Token not found.` and `No workspace selected.` (the
        key is no longer bound to a workspace).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            message: Unauthenticated.
    PaymentRequired:
      description: >-
        TryPost Cloud only: the workspace's account has no active subscription
        or trial. Body: `{"message": "Active subscription required."}`.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            message: Active subscription required.
    Forbidden:
      description: >-
        The request is not allowed. API keys work only for workspace admins (the
        account owner or a member marked as admin): otherwise every request
        returns `Insufficient workspace permissions.`. Other bodies: `Workspace
        access denied.` (the key's user left the workspace) and `Personal access
        token required.` (an MCP OAuth token was sent) and `This action is
        unauthorized.` (the note belongs to another member).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
    ValidationError:
      description: Validation failed.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ValidationErrorBody'
    TooManyRequests:
      description: 'Rate limit exceeded. Limits: 60 requests per minute per workspace.'
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/RateLimitErrorBody'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Workspace API key from Settings → API Keys.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.