Skip to main content
Webhooks

Create new webhook endpoint

The endpoint's signing secret is included in this response only — it cannot be read again later, but can be rotated at any time. The number of webhook endpoints is subject to your plan's limits (403 when exceeded).

POST
/webhooks
Authorizationstringheaderrequired

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
descriptionstring | null

Optional label to help you identify the endpoint.

Maximum string length: 255
enabledboolean

Whether the endpoint receives deliveries. Defaults to true.

eventsenum<string>[]

The event types this endpoint should receive. Canonical names: transactions.created, transactions.updated, balance.updated, holdings.updated, account.created, account.updated, account.deleted. Legacy aliases (bank_account.created, bank_account.updated, bank_account.deleted) are accepted but cannot be mixed in the same array with their canonical counterparts.

Minimum array length: 1
financial_accountsinteger[] | null

Limit deliveries to these financial account IDs. Omit or pass null to receive events for all accounts.

omit_sensitive_identifiersenum<string>

When true, sensitive account identifiers (IBAN/BBAN) are omitted from delivered payloads. Must be true for Zapier endpoints.

Available options: yes, on, 1, 1, true, true
payload_versionenum<string>

Shape of payloads delivered to this endpoint. Defaults to v2 (canonical account.* event names + financial_account payload key). Pass v1 to opt into the legacy shape (bank_account.* event-type aliases + bank_account payload key) — only useful for clients migrating an existing integration. Pinned at creation; updates are ignored. If omitted, the version is inferred from the events array: any bank_account.* subscription implies v1, otherwise v2.

Available options: v1, v2
typeenum<string>

WEBHOOK (default) for a standard endpoint, ZAPIER for an endpoint used with the Zapier integration, or N8N for an endpoint registered by the Synci n8n trigger node.

Available options: WEBHOOK, ZAPIER, N8N
urlstringrequired

The HTTPS URL that will receive event deliveries.

Maximum string length: 512

Response

application/json
dataobjectrequired
messagestringrequired