Skip to content

Create

POST
/api/managing-entity/{managingEntityIdentifier}/webhook
curl --request POST \
--url https://api.wink.travel/api/managing-entity/d5b8a3c2-9e6f-4a1b-8d34-7c2e1f0a5b69/webhook \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'Wink-Version: 2.0' \
--data null

Registers a new webhook subscription for the managing entity and returns the persisted record. The secret is returned only in this response.

managingEntityIdentifier
required
string
""

Identifier of the managing entity that will own the webhook

Example
d5b8a3c2-9e6f-4a1b-8d34-7c2e1f0a5b69
Wink-Version
string
default: 2.0.0
Allowed values: 2.0

Webhook configuration including the target callback URL and the list of event types to subscribe to

Media typeapplication/json

Request payload for creating or updating a webhook subscription, including the target endpoint URL, owning entity, and the list of event types to subscribe to.

object
enabled
required

Whether this webhook is actively subscribed to events.

boolean
default: true
Example
true
entity
required

The managing entity (account owner) that will own this webhook.

object
identifier
required

Unique managing entity (account owner) identifier.

string format: uuid
"" >= 1 characters
Example
d5b8a3c2-9e6f-4a1b-8d34-7c2e1f0a5b69
name
required

Display name of the managing entity.

string
"" >= 1 characters
Example
The Siam Residences, Bangkok
Example
{
"identifier": "d5b8a3c2-9e6f-4a1b-8d34-7c2e1f0a5b69",
"name": "The Siam Residences, Bangkok"
}
eventList
required
Array<string>
eventUrl
required

HTTPS endpoint URL to POST events to. Must be a valid, publicly accessible URL.

string format: uri
"" >= 1 characters
Example
https://api.example.com/webhooks/wink/events
name
required

Descriptive name of this webhook, e.g. ‘Booking confirmation sync’ or ‘Payment notifications’.

string
"" >= 1 characters
Example
Booking confirmation sync
Example
{
"enabled": true,
"entity": {
"identifier": "d5b8a3c2-9e6f-4a1b-8d34-7c2e1f0a5b69",
"name": "The Siam Residences, Bangkok"
},
"eventList": [
"booking.created"
],
"eventUrl": "https://api.example.com/webhooks/wink/events",
"name": "Booking confirmation sync"
}

Webhook created. The secret is returned only in this response.

Media typeapplication/json

Returned exactly once, on create and on secret rotation: the webhook and its plaintext signing secret. Store the secret now — it cannot be retrieved later.

object
secret
required

Plaintext signing secret (whsec_…). Shown once.

string
""
webhook
required

Lightweight projection of a webhook subscription that delivers HTTP POST notifications to a configured endpoint whenever subscribed events occur on the Wink platform.

object
createdDate

Datetime this record was first created

string | null format: date-time
""
enabled

Whether this webhook is actively subscribed to events.

boolean
default: true
eventList
Array<string>
eventUrl

HTTPS endpoint URL to POST events to.

string format: uri
""
id

Unique identifier for this record.

string format: uuid
""
lastUpdate

Datetime this record was last updated

string | null format: date-time
""
name

Descriptive name of this webhook, e.g. ‘Booking confirmation sync’ or ‘Payment notifications’.

string
""
ownerIdentifier

Unique managing entity (owner) identifier

string format: uuid
""
ownerName

Display name of the managing entity that owns this webhook.

string
""
previousSecretExpiresAt

Until when the previous secret is still accepted after a rotation.

string format: date-time
""
secretHint

Last four characters of the signing secret. The secret itself is returned only once, on create and rotate.

string
""
userIdentifier

Unique authenticated user identifier

string format: uuid
""
version

Optimistic-locking version. Echo this value back as an If-Match request header on a conditional update; the server responds 409 if the record changed in the meantime. Null when this projection has no backing versioned document, in which case no conditional update is possible.

integer | null format: int64
""
key
additional properties
""
Example

Bad Request — missing or invalid request parameter or body

Media typeapplication/problem+json
object
detail
string
instance
string format: uri
properties
object
key
additional properties
status
integer format: int32
title
string
type
string format: uri
key
additional properties
""
Example

Unauthorized — authentication is required or the session has expired

Media typeapplication/problem+json
object
detail
string
instance
string format: uri
properties
object
key
additional properties
status
integer format: int32
title
string
type
string format: uri
key
additional properties
""
Example

Forbidden — authenticated but lacking the required permission or scope

Media typeapplication/problem+json
object
detail
string
instance
string format: uri
properties
object
key
additional properties
status
integer format: int32
title
string
type
string format: uri
key
additional properties
""
Example

Not Found — the requested resource does not exist

Media typeapplication/problem+json
object
detail
string
instance
string format: uri
properties
object
key
additional properties
status
integer format: int32
title
string
type
string format: uri
key
additional properties
""
Example

Method Not Allowed — the HTTP verb is not supported on this endpoint

Media typeapplication/problem+json
object
detail
string
instance
string format: uri
properties
object
key
additional properties
status
integer format: int32
title
string
type
string format: uri
key
additional properties
""
Example

Conflict — the resource was modified by someone else since you read it; re-read it and retry with the new version

Media typeapplication/problem+json
object
detail
string
instance
string format: uri
properties
object
key
additional properties
status
integer format: int32
title
string
type
string format: uri
key
additional properties
""
Example

Unsupported Media Type — use application/json

Media typeapplication/problem+json
object
detail
string
instance
string format: uri
properties
object
key
additional properties
status
integer format: int32
title
string
type
string format: uri
key
additional properties
""
Example

Internal Server Error — an unexpected failure occurred on the server

Media typeapplication/problem+json
object
detail
string
instance
string format: uri
properties
object
key
additional properties
status
integer format: int32
title
string
type
string format: uri
key
additional properties
""
Example

Service Unavailable — a downstream dependency is unreachable

Media typeapplication/problem+json
object
detail
string
instance
string format: uri
properties
object
key
additional properties
status
integer format: int32
title
string
type
string format: uri
key
additional properties
""
Example