Skip to main content
POST
Create Source

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

stream_id
string<uuid>
required
workspace
string
required

Slug of the workspace the request acts in

Maximum string length: 120
Pattern: ^[a-z0-9]+(?:-[a-z0-9]+)*$

Body

application/json

A webhook source on an existing stream, with no trigger.

webhook_type
string
required

One of GET /streams/source-types.

Required string length: 1 - 50
config
Config · object

The type's plain settings, e.g. shop_id.

credentials
Credentials · object

The type's credential fields, each a value or {secret_id} of a workspace secret. Write-only: never returned.

Response

Successful Response

allowed_methods
string[] | null
required
created_at
string<date-time>
required
id
string<uuid>
required
kind
string
required
webhook_id
string | null
required
webhook_type
string | null
required
webhook_url
string | null
required

Public URL senders post to; null for non-webhook sources.

signature_scheme
WebhookSignatureScheme · object | null

How a sender signs for a type verified by configurable HMAC; null otherwise.

signing_secret
string | null

Issued when the type's signing secret is optional and none was given; shown this once only.

trigger_id
string<uuid> | null

The webhook trigger that owns this source; null for a source added directly.

Last modified on October 8, 2026