Create, update, or delete a webhook subscription, or rotate its secret
manage_webhookCreate and manage webhooks for Featureflip events: add receiver URLs, update subscriptions, rotate or retire signing secrets, and control projects, environments, or event types.
Instructions
action=create requires name + url and returns the signing secret. action=update/delete/rotate_secret/retire_secret require id. update changes only the fields you pass and keeps the rest; pass an empty list to widen that filter back to "all". projects take project keys or ids; environments take "/" keys (e.g. "web/production") or ids. eventTypes come from list_webhooks → availableEventTypes. create and rotate_secret return a secret that is NEVER shown again: relay it to the user verbatim so they can store it. rotate_secret adds a new active secret while the old one keeps signing; retire_secret (secretId from list_webhooks) removes one and is refused for the last active secret. A project-restricted service token must list at least one project, all in its scope. Requires an Admin token. A 404 on every webhook call means webhooks are not enabled for the organization.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| id | No | Subscription id; required for everything except create | |
| url | No | Receiver URL; required for create | |
| name | No | Required for create | |
| action | Yes | ||
| enabled | No | update only; subscriptions are created enabled | |
| projects | No | Project keys or ids to cover; empty or omitted on create = all | |
| secretId | No | Required for retire_secret | |
| eventTypes | No | Event types to send; empty or omitted = all | |
| environments | No | "<project>/<environment>" keys or environment ids; empty or omitted on create = all | |
| idempotency_key | No | Idempotency-Key header for create / rotate_secret |