Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Body

application/json

Where to post, and what to post about.

url
string
required

An https url, at most 2000 characters, with no credentials in it.

Maximum string length: 2000
events
enum<string>[]
required

At least one event. An unknown name is refused rather than ignored.

Minimum array length: 1

An event to subscribe to.

Available options:
run.ended,
run.needs_user_control,
schedule.triggered,
fulfilment.changed

Response

The subscription, and its signing secret. The only time the secret appears.

webhook
object
required
secret
string
required

The signing secret. Returned once. Store it now.