Customer webhooks
Current release · Updated October 2, 2026
DryKraft Customer webhooks reference: methods, permissions, request fields, response shapes, examples and current limits. Read authentication and error handling first.
/api/developer/webhooks/eventsRead event catalogue
Access: Owner or admin · Success: 200
Current built-in/custom CRM record events and supported Finance, team, Outreach and billing lifecycle events. Credentials and security events are excluded. Refresh before registering if schemas changed.
No request body is required.
Response
| Field | Type | Required | Details |
|---|---|---|---|
events | string[] | No |
curl --request GET \
--url 'https://app.drykraft.com/api/developer/webhooks/events' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>'/api/developer/webhooks/List customer webhooks
Access: Owner or admin · Success: 200
25 endpoints per cursor page, including disabled endpoints. No signing secret or ciphertext is returned. Browser session administrator access only.
Query parameters
| Parameter | Type | Required | Details |
|---|---|---|---|
cursor | uuid | No |
No request body is required.
Response
| Field | Type | Required | Details |
|---|---|---|---|
items | CustomerWebhook[] | No | |
next_cursor | string or null | No |
curl --request GET \
--url 'https://app.drykraft.com/api/developer/webhooks/' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>'/api/developer/webhooks/Register customer webhook
Access: Owner or admin · Success: 201
Current password and active plan required; shared approval limit 30/15 min. Up to 50 retained endpoints/workspace and 100 unique subscribed event types. Public DNS and HTTPS:443 are validated. Same UUID/normalized original settings returns 200/secret=null. Events committed after registration enqueue immutable signed notification envelopes atomically; historical events are not backfilled.
JSON request
| Field | Type | Required | Details |
|---|---|---|---|
id | uuid | Yes | |
name | string | Yes | Webhook name Max 100 characters. |
url | string | Yes | Public HTTPS URL; no credentials/query/fragment; port 443 Max 2048 characters. |
events | string[] | Yes | Min 1 items. Max 100 items. |
password | string | Yes | Max 128 characters. |
Response
| Field | Type | Required | Details |
|---|---|---|---|
webhook | CustomerWebhook | No | |
secret | string or null | No | One-time signing secret, only in first 201 response. Store privately. |
curl --request POST \
--url 'https://app.drykraft.com/api/developer/webhooks/' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>' \
--header 'Content-Type: application/json' \
--data '{
"id": "00000000-0000-4000-8000-000000000001",
"name": "<Webhook name>",
"url": "<Public HTTPS URL; no credentials/query/fragment; port 443>",
"events": [
"<Unique supported event type>"
],
"password": "<value>"
}'/api/developer/webhooks/{id}Update or disable webhook
Access: Owner or admin · Success: 200
Current version required. New destination, expanded subscriptions or reactivation requires current password. Enabled changes require active billing; disabling is allowed after expiry. Pending deliveries to changed destinations/removed events or disabled endpoints cancel. An accepted in-flight request can finish before this update. No queued historical event is forwarded to a new destination.
JSON request
| Field | Type | Required | Details |
|---|---|---|---|
name | string | Yes | Webhook name Max 100 characters. |
url | string | Yes | Public HTTPS URL; no credentials/query/fragment; port 443 Max 2048 characters. |
events | string[] | Yes | Min 1 items. Max 100 items. |
enabled | boolean | Yes | Enable future event delivery |
version | integer | Yes | Positive optimistic version returned by the latest read. Refresh on 409; do not overwrite stale changes. Min 1. |
password | string | No | Max 128 characters. |
Response
Use CustomerWebhook.
curl --request PUT \
--url 'https://app.drykraft.com/api/developer/webhooks/00000000-0000-4000-8000-000000000001' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>' \
--header 'Content-Type: application/json' \
--data '{
"name": "<Webhook name>",
"url": "<Public HTTPS URL; no credentials/query/fragment; port 443>",
"events": [
"<Unique supported event type>"
],
"enabled": false,
"version": 1
}'/api/developer/webhooks/{id}/rotateRotate webhook signing secret
Access: Owner or admin · Success: 201
Current password/version and active plan required. Replace encrypted signing secret immediately; subsequent attempts, including retries, use the new secret. In-flight request can finish. New operation UUID returns 201/one-time secret; identical completed retry 200/secret=null. No automatic grace period for the former secret.
JSON request
| Field | Type | Required | Details |
|---|---|---|---|
id | uuid | Yes | |
version | integer | Yes | Positive optimistic version returned by the latest read. Refresh on 409; do not overwrite stale changes. Min 1. |
password | string | Yes | Max 128 characters. |
Response
| Field | Type | Required | Details |
|---|---|---|---|
webhook | CustomerWebhook | No | |
secret | string or null | No | One-time signing secret, only in first 201 response. Store privately. |
curl --request POST \
--url 'https://app.drykraft.com/api/developer/webhooks/00000000-0000-4000-8000-000000000001/rotate' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>' \
--header 'Content-Type: application/json' \
--data '{
"id": "00000000-0000-4000-8000-000000000001",
"version": 1,
"password": "<value>"
}'/api/developer/webhooks/{id}/deliveriesRead delivery history
Access: Owner or admin · Success: 200
25 tenant-scoped delivery summaries per cursor page. Automatic retry delays after failure are 60, 300, 1800 and 7200 seconds, at most 5 attempts/cycle. Fifth failure disables the endpoint and cancels its other pending deliveries. Billing expiry defers sends 15 minutes without using an attempt. History has sanitized errors/statuses, never receiver response bodies.
Query parameters
| Parameter | Type | Required | Details |
|---|---|---|---|
cursor | uuid | No |
No request body is required.
Response
| Field | Type | Required | Details |
|---|---|---|---|
webhook | CustomerWebhook | No | |
items | WebhookDelivery[] | No | |
next_cursor | string or null | No |
curl --request GET \
--url 'https://app.drykraft.com/api/developer/webhooks/00000000-0000-4000-8000-000000000001/deliveries' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>'/api/developer/webhooks/{id}/deliveries/{deliveryId}Inspect delivered envelope and attempts
Access: Owner or admin · Success: 200
Immutable exact envelope plus latest 50 append-only completed attempt rows, newest first. Each row records attempt, secret_version, HTTP status/sanitized error and start/completion time. A process loss after acceptance can leave no completed attempt; receiver must deduplicate the delivery ID.
No request body is required.
Response
| Field | Type | Required | Details |
|---|---|---|---|
id | uuid | No | |
endpoint_id | uuid | No | |
event_id | uuid | No | |
event_type | string | No | Business event type |
state | queued | retrying | succeeded | failed | cancelled | No | Delivery state |
attempts | integer | No | Total completed attempts |
cycle_attempts | integer | No | Attempts since creation or latest replay |
version | integer | No | Positive optimistic version returned by the latest read. Refresh on 409; do not overwrite stale changes. Min 1. |
next_attempt_at | string | No | Timestamp |
last_status | integer or null | No | |
last_error | string or null | No | |
created_at | string | No | Timestamp |
completed_at | string or null | No | |
payload | WebhookEnvelope | No | |
attempt_history | object[] | No |
curl --request GET \
--url 'https://app.drykraft.com/api/developer/webhooks/00000000-0000-4000-8000-000000000001/deliveries/00000000-0000-4000-8000-000000000001' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>'/api/developer/webhooks/{id}/deliveries/{deliveryId}/replayReplay failed delivery
Access: Owner or admin · Success: 200
Current failed-delivery version and acknowledge_duplicate=true required. Restore/reapprove the original destination/event and enable endpoint first. Active billing required. Stable operation UUID resets the retry cycle once; exact retries recover the recorded result. Original body, event ID and delivery ID remain; new timestamp/signature and current secret are used. Delivery is at-least-once and can repeat external effects.
JSON request
| Field | Type | Required | Details |
|---|---|---|---|
id | uuid | Yes | |
version | integer | Yes | Positive optimistic version returned by the latest read. Refresh on 409; do not overwrite stale changes. Min 1. |
acknowledge_duplicate | true | Yes |
Response
Use WebhookDelivery.
curl --request POST \
--url 'https://app.drykraft.com/api/developer/webhooks/00000000-0000-4000-8000-000000000001/deliveries/00000000-0000-4000-8000-000000000001/replay' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>' \
--header 'Content-Type: application/json' \
--data '{
"id": "00000000-0000-4000-8000-000000000001",
"version": 1,
"acknowledge_duplicate": true
}'