Create a webhook endpoint
Add an endpoint for the events you choose and get its signing secret.
This is the only response that includes the signing secret, so store it now. Every other response shows only secret_hint.
Body
urlstring RequiredAn https:// address on the public internet, up to 2048 characters. Private, loopback and link-local hosts are refused.event_typesarray RequiredThe types to receive, at least one. See event types.descriptionstringA note for your team, up to 120 characters.enabledbooleanDefaults totrue.
Errors
- 400
invalid_requestA field is missing, unknown or out of range.fieldnames it.
Any request can also fail on its key or its body. See errors.
Request
curl -X POST "https://dash.402pay.co/api/v1/webhooks" \ -H "Authorization: Bearer $PAY402_SECRET_KEY" \ -H "Content-Type: application/json" \ -d '{ "url": "https://example.com/webhooks/402pay", "description": "Fulfill orders", "event_types": ["payment.succeeded", "payment.failed"] }'Response201 Created
{ "data": { "id": "whk_GFAKLrE8wkBwF4WL", "kind": "webhook", "url": "https://example.com/webhooks/402pay", "description": "Fulfill orders", "event_types": ["payment.succeeded", "payment.failed"], "enabled": true, "secret_hint": "whsec_••••X/LG", "created_at": "2026-09-26T21:22:47.012Z", "updated_at": "2026-09-26T21:22:47.012Z", "secret": "whsec_bM0XCID9vQtL0CuhH+4f/aQMZm7pX/LG" }}