Skip to content

Update a webhook endpoint

Change an endpoint's URL, events or description, or turn it off.

Send only what changes. event_types replaces the whole list. Turning an endpoint off with enabled stops new deliveries without losing its settings.

Path

  • id string Required
    The webhook endpoint's ID, such as whk_GFAKLrE8wkBwF4WL.

Body

  • url string
    An https:// address on the public internet, up to 2048 characters. Private, loopback and link-local hosts are refused.
  • event_types array
    The types to receive, at least one. See event types.
  • description string
    A note for your team.
  • enabled boolean
    Whether the endpoint receives deliveries.

Errors

  • 400 invalid_request
    A field is missing, unknown or out of range. field names it.
  • 404 not_found
    No webhook endpoint with that ID belongs to your business.

Any request can also fail on its key or its body. See errors.

Request
curl -X PATCH "https://api.402pay.co/api/v1/webhooks/whk_GFAKLrE8wkBwF4WL" \
  -H "Authorization: Bearer $PAY402_SECRET_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "event_types": ["payment.succeeded", "payment.underpaid", "payment.failed"]
  }'
Response200 OK
{
  "data": {
    "id": "whk_GFAKLrE8wkBwF4WL",
    "kind": "webhook",
    "url": "https://example.com/webhooks/402pay",
    "description": "Fulfill orders",
    "event_types": ["payment.succeeded", "payment.underpaid", "payment.failed"],
    "enabled": true,
    "secret_hint": "whsec_••••X/LG",
    "created_at": "2026-09-26T21:22:47.012Z",
    "updated_at": "2026-09-26T21:23:17.086Z"
  }
}