Endpoints webhook
Endpoints HTTP configurés par le tenant qui reçoivent les notifications d'événement (changements de statut de facture, mises à jour d'e-reporting, ...) envoyées par Scribee, y compris la rotation du secret pour vérifier les signatures des webhooks.
List webhook endpoints for a workspace
Returns a paginated list of webhook endpoints for the specified workspace. Never includes the signing_secret.
Create a webhook endpoint
Creates a new webhook endpoint in the specified workspace. The response includes the signing_secret exactly once - it is never returned again except via regenerate_secret.
Retrieve a webhook endpoint by ID
Returns a single webhook endpoint by ID. Never includes the signing_secret.
Update a webhook endpoint
Updates an existing webhook endpoint. event_type is immutable and silently ignored if present in the request body. Only the OAuth application that created the endpoint may update it: an endpoint created by another application of the same workspace is visible on GET but returns 403 here. Endpoints created from the Scribee web interface belong to no application and are managed from the web interface only - they return 403 for every OAuth application, whichever one calls.
Delete a webhook endpoint
Permanently deletes a webhook endpoint. Only the OAuth application that created the endpoint may delete it: an endpoint created by another application of the same workspace is visible on GET but returns 403 here. Endpoints created from the Scribee web interface belong to no application and are managed from the web interface only - they return 403 for every OAuth application, whichever one calls.
Regenerate a webhook endpoint's signing secret
Generates a new signing_secret for the endpoint, invalidating the previous one. The new secret is returned exactly once in this response. Only the OAuth application that created the endpoint may rotate its secret: an endpoint created by another application of the same workspace is visible on GET but returns 403 here. Endpoints created from the Scribee web interface belong to no application and are managed from the web interface only - update, delete and secret rotation all return 403 for every OAuth application, whichever one calls.