View as Markdown

Create a webhook subscription

POST /v1/webhooks
Base URL
https://api.isnotai.com

Authenticate with Authorization: Bearer aik_v1_... (preferred) or the x-api-key header. Keys are region-bound. Authentication

Available Regions 2 regions

NOT idempotent: every successful call creates a new subscription with a fresh id and a fresh signing secret, and duplicate URLs/event types are not deduplicated. If a create times out, reconcile with GET /v1/webhooks before re-creating, or you will register the same endpoint twice (double deliveries). The 201 response is the ONLY place the secret appears (besides rotate-secret); store it immediately. Returns 402 PLAN_LIMIT_REACHED when creating an enabled subscription past the plan cap on active subscriptions (disabled subscriptions do not count).

application/json

Body

url
string Required

Delivery URL. https (recommended) or http, port 443 or 80 only, no userinfo. Private, loopback, link-local, CGNAT, and cloud-metadata hosts are rejected with 400 INVALID_URL.

Maximum length is 2048.
eventType
string Required

Event type name (string). Requests accept the name case-insensitively; responses return the PascalCase form shown here. Integers never appear on the wire.

Values are BotDetected, SessionAnomaly, ThresholdExceeded, AlertTriggered, ReportReady, SessionCorrelated, WritingSessionScored.
name
string

Optional display name for the subscription.

threshold
any
enabled
boolean

Whether the subscription starts active. Defaults to true.

Default is true.

Responses

Any authenticated route can also return 401 (missing or invalid key), 429 RATE_LIMITED (edge rate limit; Retry-After is an integer number of seconds), and 5xx errors, even where not listed below. See Error Handling and Rate Limits.

201 application/json

Payload of WebhookSubscriptionCreatedResponse

Show 1 response attribute Hide response attributes
data
object
Show 16 data attributes Hide data attributes
id
string
integrationId
string
url
string
eventType
string

Event type name (string). Requests accept the name case-insensitively; responses return the PascalCase form shown here. Integers never appear on the wire.

Values are BotDetected, SessionAnomaly, ThresholdExceeded, AlertTriggered, ReportReady, SessionCorrelated, WritingSessionScored.
name
string
enabled
boolean
threshold
any
createdAt
string(date-time)
updatedAt
string(date-time)
lastDeliveryAt
string(date-time)
lastDeliveryStatus
string

Outcome of the most recent delivery attempt (string). Null until the first delivery.

Values are Pending, Delivered, Failed, MaxRetriesExceeded, PermanentFailure, PoisonAborted, null.
disabledAt
string(date-time)
disabledReason
string
disabledFailureClass
string
disabledDeliveryId
string
secret
string

One-time signing secret for X-Webhook-Signature verification. Returned ONLY by POST /v1/webhooks and POST /v1/webhooks/{subscriptionId}/rotate-secret; no other response ever includes it. Store it immediately; if lost, rotate.

400 application/json

Payload of ErrorEnvelope

Show 1 response attribute Hide response attributes
error
object
Show 3 error attributes Hide error attributes
code
string Required
message
string Required
details
object Required

Always present and null unless the error carries field-level context (validation errors set details.field to the offending parameter name).

401 application/json

Payload of ErrorEnvelope

Show 1 response attribute Hide response attributes
error
object
Show 3 error attributes Hide error attributes
code
string Required
message
string Required
details
object Required

Always present and null unless the error carries field-level context (validation errors set details.field to the offending parameter name).

402 application/json

Payload of ErrorEnvelope

Show 1 response attribute Hide response attributes
error
object
Show 3 error attributes Hide error attributes
code
string Required
message
string Required
details
object Required

Always present and null unless the error carries field-level context (validation errors set details.field to the offending parameter name).

POST /v1/webhooks
curl --request POST \
  --url https://api.isnotai.com/v1/webhooks \
  --header 'Authorization: Bearer aik_v1_YOUR_API_KEY' \
  --header 'Content-Type: application/json' \
  --data '{"url":"https://example.com","eventType":"BotDetected"}'
import requests

url = "https://api.isnotai.com/v1/webhooks"

payload = {
    "url": "https://example.com",
    "eventType": "BotDetected"
}
headers = {
    "Authorization": "Bearer aik_v1_YOUR_API_KEY",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
const fetch = require('node-fetch');

const url = 'https://api.isnotai.com/v1/webhooks';
const options = {
  method: 'POST',
  headers: {
    Authorization: 'Bearer aik_v1_YOUR_API_KEY',
    'Content-Type': 'application/json'
  },
  body: '{"url":"https://example.com","eventType":"BotDetected"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
using System.Net.Http.Headers;
var client = new HttpClient();
var request = new HttpRequestMessage
{
    Method = HttpMethod.Post,
    RequestUri = new Uri("https://api.isnotai.com/v1/webhooks"),
    Headers =
    {
        { "Authorization", "Bearer aik_v1_YOUR_API_KEY" },
    },
    Content = new StringContent("{\"url\":\"https://example.com\",\"eventType\":\"BotDetected\"}")
    {
        Headers =
        {
            ContentType = new MediaTypeHeaderValue("application/json")
        }
    }
};
using (var response = await client.SendAsync(request))
{
    response.EnsureSuccessStatusCode();
    var body = await response.Content.ReadAsStringAsync();
    Console.WriteLine(body);
}

Try it

Collapse

Sent to the API as Authorization: Bearer aik_v1_.... Held only in this tab's input element; re-enter on each browser tab. The docs site never receives or stores it.

Request examples
{
  "url": "https://example.com",
  "eventType": "BotDetected"
}
201 Response examples
{
  "data": {
    "id": "example-id-123",
    "integrationId": "string",
    "url": "https://example.com",
    "eventType": "BotDetected",
    "name": "string",
    "enabled": false,
    "threshold": null,
    "createdAt": "2024-01-01T00:00:00Z",
    "updatedAt": "2024-01-01T00:00:00Z",
    "lastDeliveryAt": "2024-01-01T00:00:00Z",
    "lastDeliveryStatus": "Pending",
    "disabledAt": "2024-01-01T00:00:00Z",
    "disabledReason": "string",
    "disabledFailureClass": "string",
    "disabledDeliveryId": "string",
    "secret": "string"
  }
}
400 Response examples
{
  "error": {
    "code": "string",
    "message": "string",
    "details": {}
  }
}
401 Response examples
{
  "error": {
    "code": "string",
    "message": "string",
    "details": {}
  }
}
402 Response examples
{
  "error": {
    "code": "string",
    "message": "string",
    "details": {}
  }
}