> ## Documentation Index
> Fetch the complete documentation index at: https://developers.wachat.net/llms.txt
> Use this file to discover all available pages before exploring further.

# Create webhooks

> Registers an outbound webhook endpoint for the workspace. Wachat sends subscribed message, delivery, contact, device, broadcast, and campaign events to the URL; use a signing secret to verify that deliveries came from Wachat.



## OpenAPI

````yaml /openapi.json post /webhooks
openapi: 3.1.0
info:
  title: Wachat API
  version: v1
  description: >-
    Wachat REST API. Authenticate with a workspace API key: send it as
    `Authorization: Bearer <key>`. Generate keys in the dashboard under
    Developers / API.
servers:
  - url: https://crm.wachat.net/api/v1
security:
  - http: []
tags:
  - name: Message
    description: >-
      Send a single WhatsApp message — text, media (image / video / document /
      audio) or a location pin — to one number, then read its delivery status or
      your message history. A file can be attached directly as a multipart
      `media` field or referenced by a public URL.
  - name: Template
    description: >-
      Create, list and manage your approved WhatsApp templates, and send a
      template to one number with your own header, body variables and button
      values. Use this for utility / marketing sends that need a pre-approved
      template — including one with a PDF / document header (pass the file's
      public URL as the header, e.g. from the Media endpoint).
  - name: Media
    description: >-
      Upload a file once (multipart / form-data, field name `file`, up to 16 MB)
      and get back a hosted public URL you can reuse across sends — for example
      a PDF to use as a document-header on a template, or an image on a message.
  - name: Contact
    description: >-
      Full create / read / update / delete over your contacts and leads,
      including search by number, tags and custom attributes.
  - name: ContactGroup
    description: >-
      Organise contacts into groups: create groups, list them, and add or remove
      members — handy for targeting broadcasts and campaigns.
  - name: Broadcast
    description: >-
      Send the same message to many contacts at once and track each broadcast's
      progress and per-recipient delivery.
  - name: Campaign
    description: >-
      Create, start, pause and monitor drip / marketing campaigns and their
      recipients.
  - name: Scheduled
    description: >-
      Schedule a WhatsApp send for a future time, list upcoming scheduled
      messages, and cancel one before it goes out.
  - name: AutoReply
    description: >-
      Manage keyword auto-replies — the automatic responses that fire when an
      inbound message matches a rule.
  - name: Flow
    description: >-
      Enroll a contact into an automation flow (chatbot) and manage your flows
      through the API.
  - name: Device
    description: >-
      List the WhatsApp numbers / devices connected to your workspace and check
      each one's connection status.
  - name: Webhook
    description: >-
      Register and manage webhook endpoints so Wachat POSTs real-time events
      (message received / sent / delivered / read / failed, plus campaign and
      contact events) to your server. When you set a signing secret each
      delivery carries an HMAC-SHA256 signature header you can verify.
  - name: Deal
    description: >-
      Manage sales-pipeline deals — create, list, update and move deals between
      stages.
  - name: Conversation
    description: >-
      Read your workspace inbox: list chat threads (conversations) and fetch the
      messages inside a thread.
  - name: Account
    description: Read your account details, plan, limits and message-credit usage.
paths:
  /webhooks:
    post:
      tags:
        - Webhook
      summary: Create webhooks
      description: >-
        Registers an outbound webhook endpoint for the workspace. Wachat sends
        subscribed message, delivery, contact, device, broadcast, and campaign
        events to the URL; use a signing secret to verify that deliveries came
        from Wachat.
      operationId: v1.webhooks.store
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/StoreWebhookRequest'
      responses:
        '201':
          description: Resource created successfully.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items: {}
                  meta:
                    type: string
                required:
                  - data
                  - meta
        '422':
          $ref: '#/components/responses/ValidationException'
          description: Request failed.
components:
  schemas:
    StoreWebhookRequest:
      type: object
      description: >-
        Register an outbound webhook endpoint for the current workspace.
        Scramble

        reads these rules to document the request body. Mirrors the validation
        in

        the in-app WebhooksController::store.


        The platform POSTs a JSON envelope to the registered `url` whenever a

        subscribed event fires. When a signing `secret` is configured the
        request

        carries an `X-Wachat-Signature` header (HMAC-SHA256 of the body).
      properties:
        url:
          type: string
          format: uri
          description: Public HTTPS endpoint the platform POSTs events to. Required.
          maxLength: 2048
        name:
          type:
            - string
            - 'null'
          description: Optional friendly label shown in the dashboard.
          maxLength: 191
        secret:
          type:
            - string
            - 'null'
          description: |-
            Optional HMAC signing secret. When set, deliveries carry an
            X-Wachat-Signature header so receivers can verify authenticity.
          maxLength: 191
        active:
          type:
            - boolean
            - 'null'
          description: |-
            Whether the endpoint is active and should receive events.
            Defaults to true.
        events:
          type:
            - array
            - 'null'
          description: >-
            Event names to subscribe to. Omit (or pass ["*"]) to receive all.

            Supported events fired by the system:

            message_received                 — inbound message received

            message_sent                     — outbound message sent

            message_delivered                — outbound message delivered

            message_read                     — outbound message read

            message_failed                   — outbound message failed

            broadcast_created                — broadcast created

            broadcast_status_updated         — broadcast status changed

            broadcast_message_status_updated — per-recipient broadcast status
            changed

            campaign_created                 — campaign created

            campaign_status_updated          — campaign status changed

            campaign_contact_status_updated  — per-contact campaign status
            changed

            campaign_contact_clicked         — campaign contact clicked a link

            campaign_contact_replied         — campaign contact replied

            contact_opt_in                   — contact opted in

            contact_updated                  — contact updated

            device_status_updated            — device (number) status changed

            "*"                              — subscribe to every event
          items:
            type: string
            maxLength: 64
      required:
        - url
      title: StoreWebhookRequest
  responses:
    ValidationException:
      description: Validation error
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
                description: Errors overview.
              errors:
                type: object
                description: A detailed description of each field that failed validation.
                additionalProperties:
                  type: array
                  items:
                    type: string
            required:
              - message
              - errors
  securitySchemes:
    http:
      type: http
      scheme: bearer

````