Incantory
Sign in

Webhooks API

10 operations. Authentication, errors and pagination work as described in the REST API overview.

List your webhooks

GET/api/v1/webhooksToken required · scope read

Secrets are never returned after creation; secretHint shows the last four characters.

Responses: 200 OK400, 401, 403, 404, 429

Response fields
listWebhooks response fields
NameTypeDescription
itemsrequiredobject[]
Example
curl 'https://incantory.ai/api/v1/webhooks' \
  -H "Authorization: Bearer $INCANTORY_TOKEN"

Create a webhook

POST/api/v1/webhooksToken required · scope write

The URL must be https and on the public internet. Returns the signing secret once. At most 20 webhooks per account. Deliveries are POSTs with Incantory-Event, Incantory-Delivery and Incantory-Signature: t=<unix>,v1=<hex HMAC-SHA256(secret, "<t>.<body>")> headers; see /docs/webhooks.

Request body

createWebhook body fields
NameTypeDescription
urlrequiredstringThe https endpoint that receives POSTs
eventsrequired("prompt.version.created" | "prompt.label.moved" | "prompt.published" | "prompt.deleted" | "eval.run.completed" | "eval.run.failed" | "change_request.opened" | "change_request.merged" | "make.linked" | "make.approved" | "comment.created")[]Events to deliver: prompt.version.created, prompt.label.moved, prompt.published, prompt.deleted, eval.run.completed, eval.run.failed, change_request.opened, change_request.merged, make.linked, make.approved, comment.created
descriptionstringA note for yourself
promptsstring[] | nullOnly deliver events about these prompts (owner/slug). Omit or null for every prompt you own or watch.
activebooleanDefault true

Responses: 201 OK400, 401, 403, 404, 409, 422, 429

Response fields
createWebhook response fields
NameTypeDescription
webhookrequiredobject
secretrequiredstringThe signing secret (whsec_…). Shown only in this response.
Example
curl -X POST 'https://incantory.ai/api/v1/webhooks' \
  -H "Authorization: Bearer $INCANTORY_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{"url":"https://example.com/hook","events":["prompt.version.created"]}'

Get a webhook

GET/api/v1/webhooks/{id}Token required · scope read

getWebhook parameters
NameTypeDescription
id pathrequiredstringWebhook id

Responses: 200 OK400, 401, 403, 404, 429

Response fields
getWebhook response fields
NameTypeDescription
idrequiredstring
urlrequiredstring
descriptionrequiredstring
eventsrequiredstring[]
promptsrequiredobject[] | null
activerequiredboolean
disabledAtrequiredstring | nullSet when Incantory disabled the webhook after repeated failures
failureCountrequiredinteger (-9007199254740991–9007199254740991)Consecutive failed delivery attempts
lastDeliveryAtrequiredstring | null
secretHintrequiredstringwhsec_…abcd
createdAtrequiredstring
updatedAtrequiredstring
Example
curl 'https://incantory.ai/api/v1/webhooks/{id}' \
  -H "Authorization: Bearer $INCANTORY_TOKEN"

Update a webhook (owner only)

PATCH/api/v1/webhooks/{id}Token required · scope write

active: true re-enables a webhook Incantory disabled after repeated failures (and resets the failure count). rotateSecret: true returns a new secret once; the old one stops working immediately.

updateWebhook parameters
NameTypeDescription
id pathrequiredstringWebhook id

Request body

updateWebhook body fields
NameTypeDescription
urlstring
events("prompt.version.created" | "prompt.label.moved" | "prompt.published" | "prompt.deleted" | "eval.run.completed" | "eval.run.failed" | "change_request.opened" | "change_request.merged" | "make.linked" | "make.approved" | "comment.created")[]Events to deliver: prompt.version.created, prompt.label.moved, prompt.published, prompt.deleted, eval.run.completed, eval.run.failed, change_request.opened, change_request.merged, make.linked, make.approved, comment.created
descriptionstring
promptsstring[] | null
activebooleantrue also clears an automatic disable and the failure count
rotateSecrettrueGenerate a new signing secret; the response carries it once

Responses: 200 OK400, 401, 403, 404, 409, 422, 429

Response fields
updateWebhook response fields
NameTypeDescription
webhookrequiredobject
secretstring
Example
curl -X PATCH 'https://incantory.ai/api/v1/webhooks/{id}' \
  -H "Authorization: Bearer $INCANTORY_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{}'

Delete a webhook and its delivery log

DELETE/api/v1/webhooks/{id}Token required · scope write

deleteWebhook parameters
NameTypeDescription
id pathrequiredstringWebhook id

Responses: 204 OK400, 401, 403, 404, 429

Example
curl -X DELETE 'https://incantory.ai/api/v1/webhooks/{id}' \
  -H "Authorization: Bearer $INCANTORY_TOKEN"

The delivery log (newest first)

GET/api/v1/webhooks/{id}/deliveriesToken required · scope read

Keyset-paginated with cursor; kept for 30 days.

listWebhookDeliveries parameters
NameTypeDescription
id pathrequiredstringWebhook id
cursor querystring
limit queryinteger (1–100)

Responses: 200 OK400, 401, 403, 404, 429

Response fields
listWebhookDeliveries response fields
NameTypeDescription
itemsrequiredobject[]
nextCursorrequiredstring | null
Example
curl 'https://incantory.ai/api/v1/webhooks/{id}/deliveries' \
  -H "Authorization: Bearer $INCANTORY_TOKEN"

One delivery, with its payload

GET/api/v1/webhooks/{id}/deliveries/{deliveryId}Token required · scope read

getWebhookDelivery parameters
NameTypeDescription
id pathrequiredstringWebhook id
deliveryId pathrequiredstringDelivery id

Responses: 200 OK400, 401, 403, 404, 429

Response fields
getWebhookDelivery response fields
NameTypeDescription
idrequiredstring
eventrequiredstring
eventIdrequiredstring | null
attemptrequiredinteger (-9007199254740991–9007199254740991)
statusrequired"pending" | "succeeded" | "failed"
responseCoderequiredinteger (-9007199254740991–9007199254740991) | null
responseTimeMsrequiredinteger (-9007199254740991–9007199254740991) | null
responseExcerptrequiredstring | nullFirst 2 KB of the response body
errorrequiredstring | null
nextAttemptAtrequiredstring | null
deliveredAtrequiredstring | null
createdAtrequiredstring
payloadanyThe envelope that was (or will be) sent; single-delivery reads only
Example
curl 'https://incantory.ai/api/v1/webhooks/{id}/deliveries/{deliveryId}' \
  -H "Authorization: Bearer $INCANTORY_TOKEN"

Redeliver an event

POST/api/v1/webhooks/{id}/deliveries/{deliveryId}/redeliverToken required · scope write

Sends the same envelope (same event id) as a new delivery. 409 webhook_disabled while the webhook is disabled.

redeliverWebhook parameters
NameTypeDescription
id pathrequiredstringWebhook id
deliveryId pathrequiredstringDelivery id

Responses: 202 OK400, 401, 403, 404, 409, 429

Response fields
redeliverWebhook response fields
NameTypeDescription
deliveryIdrequiredstring
Example
curl -X POST 'https://incantory.ai/api/v1/webhooks/{id}/deliveries/{deliveryId}/redeliver' \
  -H "Authorization: Bearer $INCANTORY_TOKEN"

Send a test (ping) delivery

POST/api/v1/webhooks/{id}/testToken required · scope write

Queued immediately; works on a disabled webhook, is never retried and does not count towards auto-disable. Rate-limited to 30 per hour.

testWebhook parameters
NameTypeDescription
id pathrequiredstringWebhook id

Responses: 202 OK400, 401, 403, 404, 429

Response fields
testWebhook response fields
NameTypeDescription
deliveryIdrequiredstring
Example
curl -X POST 'https://incantory.ai/api/v1/webhooks/{id}/test' \
  -H "Authorization: Bearer $INCANTORY_TOKEN"

The webhook event catalogue

GET/api/v1/webhooks/eventsPublic

Events: prompt.version.created, prompt.label.moved, prompt.published, prompt.deleted, eval.run.completed, eval.run.failed, change_request.opened, change_request.merged, make.linked, make.approved, comment.created. The test delivery sends ping.

Responses: 200 OK304, 400, 404, 429

Response fields
listWebhookEvents response fields
NameTypeDescription
itemsrequiredobject[]
Example
curl 'https://incantory.ai/api/v1/webhooks/events'