Registers an HTTPS URL that Crisphive will POST events to, and immediately sends a signed verification `ping`. If your receiver answers 2xx the endpoint is created `active`; otherwise it is created `pending_verification` (receives NO events) — fix the receiver, then re-verify it from the Crisphive dashboard, or (on the public API, where verify is not exposed) delete it and create it again. Automation platforms subscribing a REST hook should filter out the `ping` event on their side. The response includes the signing `secret` ONE TIME — store it; you verify the `Crisphive-Signature` header with it and it cannot be retrieved again. `event_types` empty = every event the calling credential may READ: `customer.*` needs customers_view, `technician.*` team_view, `job_request.*` job_view, because a subscription streams that data to your URL. Naming an event the credential cannot read is refused with WEBHOOK_EVENT_NOT_PERMITTED (403, `data.event_types` + `data.required_permissions`). The endpoint is bound to the caller's current environment (live/sandbox).
المعاملات
Idempotency-Keystringheaderاختياري
Unique key making retries safe: a repeat send with the same key replays the original response (header Idempotent-Replayed: true) instead of minting a second endpoint + secret. Reusing a key with a different body returns 422.
descriptionstringbodyاختياري
Optional human label shown in the dashboard.
event_typesarray<string>bodyاختياري
Event types to receive. Empty = every event the credential may READ (customer.* needs customers_view, technician.* team_view, job_request.* job_view); naming one it cannot read is WEBHOOK_EVENT_NOT_PERMITTED. See GET /business/webhooks/event-types.
expires_in_daysintegerbodyاختياري
Signing-secret lifetime in days. Omit for the 30-day default; 1..365 to
choose your own. When it lapses the endpoint stops delivering until you
rotate — see POST /business/webhooks/{id}/rotate-secret.
urlstringbodyمطلوب
HTTPS callback URL Crisphive will POST events to. Required; absolute http(s).