Create a webhook subscription
POST/webhooks
PostEverywhere POSTs event payloads to your URL, signed with
HMAC-SHA256 in the X-PostEverywhere-Signature header
(sha256=<hmac> over the raw body using the returned secret).
Delivery headers also include X-PostEverywhere-Event,
X-PostEverywhere-Event-Id, X-PostEverywhere-Timestamp and
X-PostEverywhere-Delivery-Id. The secret is returned ONLY on
creation. URLs are SSRF-validated (no localhost/private/metadata
addresses). Max 25 webhooks per organization
(400 limit_reached). Unknown events → 400 invalid_event_type.
Request
Responses
- 201
- 400
- 401
- 402
- 403
- 429
- 500
Created — includes the one-time signing secret
Validation error — see error.code and error.details
Missing/invalid/revoked/expired API key (codes invalid_api_key, api_key_revoked, api_key_expired, api_key_required, auth_failed). Auth-layer 401s omit error.retryable and meta.request_id.
No active subscription (code subscription_required — the error object also carries subscription_status), or insufficient AI credits (insufficient_credits) / paid plan required (upgrade_required).
API key missing the required scope (insufficient_scope), storage quota exceeded (storage_quota_exceeded), or account limit reached (account_limit_reached)
Rate limit exceeded (rate_limit_exceeded, or plan budgets post_limit_reached / daily_limit_reached on schedulePost). All 429s carry Retry-After. The API-key limiter additionally sets the X-RateLimit-* headers and error.details {limit, remaining, reset_at}.
Response Headers
Seconds to wait before retrying
Requests allowed in the window (API-key limiter only)
Requests remaining (API-key limiter only)
Unix seconds when the window resets (API-key limiter only)
Internal error (internal_error and endpoint-specific 5xx codes). Retryable.