Skip to main content
POST
Register webhook

Authorizations

Authorization
string
header
required

HS256-signed JWT bearer token, obtained via the OAuth2 client-credentials grant (see Authentication).

Body

application/json

Webhook attributes

events
enum<string>[]
required

Event types this endpoint is subscribed to. Must contain at least one.

Minimum array length: 1
Available options:
decision.allow,
decision.block,
decision.review,
decision.provisional,
decision.async.allow,
decision.async.block,
decision.async.review
url
string<uri>
required

HTTPS URL that Specter delivers event notifications to.

Example:

"https://merchant.example.com/webhooks/specter"

Response

Created webhook

Returned only on initial creation. Contains the plaintext hmac_key — store it securely, it will not be shown again.

id
string<uuid>
Example:

"2f8d4b6c-9e1a-4c7f-b3d5-8a6e2c9f4b1d"

events
string[]
Example:
hmac_key
string | null

Plaintext HMAC key. Only returned once.

Example:

"c2VjcmV0LXdlYmhvb2stc2lnbmluZy1rZXk="

inserted_at
string<date-time>
Example:

"2026-01-20T08:30:00Z"

updated_at
string<date-time>
Example:

"2026-01-20T08:30:00Z"

url
string<uri>
Example:

"https://merchant.com.example/webhooks/specter"