Skip to main content
POST
Create webhook (V2)

Overview

Creates a webhook owned by the token’s company. The plaintext HMAC signing secret is included in the response only on creation — it is never returned again. Store it securely, exactly as returned: it is 64 uppercase hexadecimal characters, and the signing key is that exact string, so its case matters (see Verifying the signature).
Rate limit: 4 req/s · 20/min · 600/hr · 14,400/day

Endpoint

POST /v2/api/webhooks

Request body

Response

200 OK — CreateWebhookResponse (extends WebhookDto)

Example response

Error responses

Authorizations

Authorization
string
header
required

JWT Bearer token obtained from POST /v2/api/authentication/token/api-key.

Lifetime: ~24 hours (86,399 seconds). Cache the token and reuse it. Re-authenticate 5 minutes before expiry.

Scoping: API key tokens are scoped by the key's company and its action set; see Token scoping.

No refresh endpoint — re-authenticate with your API key when the token expires.

Body

application/json
url
string<uri>
required

http or https. The host must contain a dot or be an IP address, must resolve, and must not resolve to a loopback, private, CGNAT, link-local or multicast address, to 0.0.0.0/8 or 240.0.0.0/4, to ::, or to an IPv6 unique-local, 6to4 or Teredo address; otherwise the response is 422. A value that cannot be parsed as a URL is not always refused: it can be accepted, and nothing is ever delivered to it.

Example:

"https://your-server.example.com/telemax-webhook"

alertIds
integer[]

Alert configuration IDs to link, at most 50 distinct. Required when isGlobal is false; ignored when it is true. Each must be of a type that can be linked (see the endpoint description).

Example:
isActive
boolean
default:true
isGlobal
boolean
default:false

Response

Successful response. warning is set when the linked alerts have different types.