Skip to navigation

Create an event subscription

View as Markdown

Authentication

AuthorizationBearer

Your Truvo API key, sent as a bearer token. The prefix selects sandbox (trv_sandbox_) or live (trv_live_).

Headers

Truvo-VersionenumRequiredDefaults to 2026-09-26

The contract revision of this request, which every operation in this document requires. This document describes 2026-09-26. Served revisions: 2026-09-26. A missing header, or one that names no served revision exactly, answers invalid_version (400), and its field error lists the served revisions in allowed_values, newest first.

Allowed values:
Idempotency-KeystringRequired

A caller-chosen request key. A key replays for at least 24 hours. The same key with the same body replays the first answer; the same key with a different body is a conflict.

Request

This endpoint expects an object.
urlstringRequiredformat: "uri"
event_typeslist of enumsRequired

Response headers

Request-Idstringformat: "^req_[0-9a-f]{16}$"

The ID of this answer. An error body repeats it as request_id.

Truvo-Versionstringformat: "^[0-9]{4}-[0-9]{2}-[0-9]{2}$"

The contract revision of this answer: the revision that the request named in Truvo-Version. A 404, and a refusal sent before Truvo knows your revision (401, 413, a 429 for failed authentication, and a 400 invalid_version), name the current revision and take its shape.

RateLimit-LimitintegerOptional
The calls this window allows, for the limit you're closest to reaching. The window is one minute or one UTC day. A fixed window allows a burst of up to twice the limit across a window edge.
RateLimit-RemainingintegerOptional
The calls left in the current window.
RateLimit-ResetintegerOptional
Seconds until the current window ends and the count resets.

Response

Create a webhook subscription to exact event types, up to 10 for each integration. The answer carries the signing secret once.
idstringformat: "^sub_[a-z0-9]{8,64}$"
environmentstring
urlstringformat: "uri"
statusenum
Allowed values:
event_typeslist of strings
The event types that the subscription receives. A create or a change names at least one. A subscription that named only a type that v1 no longer sends lists none.
signing_secretstring or null>=1 character

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
409
Conflict Error
413
Content Too Large Error
422
Unprocessable Entity Error
429
Too Many Requests Error
500
Internal Server Error
503
Service Unavailable Error