Skip to the page
Chapters

Webhook endpoints

Add a webhook endpoint

POST/api/v1/webhook_endpoints

Registers a URL to send events to. The URL must be https, with no user name, password or fragment, to a host name (not an IP address) that resolves to a public address, in test mode as well as live mode. Leave out event_types to receive every type. An organization can have at most 10 endpoints in a mode. The response carries the signing secret (secret). It is shown only in this response and cannot be read again: store it now. A request repeated with the same Idempotency-Key gets the stored reply without the secret (secret_available is false): rotate the secret to get a new one.

Needs a key with submit permission.

Request

Headers

Headers
NameTypeRequiredDescription
Idempotency-KeystringrequiredMakes the request safe to repeat: a request with the same key and body returns the first answer (the reply has an idempotent-replayed header), and the same key with a different request is refused. 1 to 255 printable characters; a UUID is a good choice.At least 1 character.At most 255 characters.Matches `^[\x21-\x7e]{1,255}$`.

Body

Body
NameTypeRequiredDescription
urlstringrequiredWhere events are sent: an https URL to a host name that resolves to a public address.At most 2048 characters.
descriptionstringoptionalA note for yourself.At most 200 characters.
event_typesarray of stringoptionalThe event types to send. Leave out for every type.At most 19 items.Each item is one of: `eligibility.completed`, `api_key.created`, `api_key.revoked`, `claim.validated`, `claim.needs_attention`, `claim.queued`, `claim.submitted`, `claim.accepted`, `claim.rejected`, `claim.status_updated`, `claim.voided`, `batch.acknowledged`, `attachment.completed`, `payer_request.received`, `era.received`, `claim.paid`, `claim.denied`, `claim.payment_reversed`, `predetermination.returned`.

Response

The endpoint, with its signing secret. Status 200.

Response fields
NameTypeDescription
idstringAn ID that starts with whe_.
objectstringAlways `webhook_endpoint`.
urlstring
descriptionstring
event_typesarray of string or nullThe event types sent to this endpoint; null for every type.Each item is one of: `eligibility.completed`, `api_key.created`, `api_key.revoked`, `claim.validated`, `claim.needs_attention`, `claim.queued`, `claim.submitted`, `claim.accepted`, `claim.rejected`, `claim.status_updated`, `claim.voided`, `batch.acknowledged`, `attachment.completed`, `payer_request.received`, `era.received`, `claim.paid`, `claim.denied`, `claim.payment_reversed`, `predetermination.returned`.
statusstringOne of: `enabled`, `disabled`.
modestringOne of: `test`, `live`.
created_atstring (date-time)
secretstringThe signing secret (whsec_...). Shown only in the response that made it: store it now. Absent when secret_available is false.
secret_availablebooleanFalse in the stored reply an Idempotency-Key replay returns: the secret is never stored for replay. Rotate the secret to get a new one.

Errors

Errors
HTTP statusCodeWhat it means
401UNAUTHORIZEDA valid API key is required. Send it as "Authorization: Bearer <key>".
403PERMISSION_DENIEDThis API key is not allowed to do that.
422INVALID_REQUESTThe request is not valid.
400IDEMPOTENCY_KEY_REQUIREDPOST and PATCH requests need an Idempotency-Key header.
422IDEMPOTENCY_KEY_REUSEDThat Idempotency-Key was already used with a different request.
409IDEMPOTENCY_KEY_IN_USEA request with that Idempotency-Key is still running. Retry shortly.
413PAYLOAD_TOO_LARGEThe request body is larger than 1 MB.
504TIMEOUTThe request took too long to finish. It may still have taken effect: look it up before sending it again with a new Idempotency-Key. What it made is found with GET /api/v1/eligibility?request_id=<this request_id>, and the same filter on /api/v1/claims and /api/v1/attachments (a key with read permission).
500INTERNALSomething went wrong on our side. Quote the request ID if you contact us.

Example

Example request

Shell
curl -X POST "https://sandbox.myclaimhouse.com/api/v1/webhook_endpoints" \
  -H "Authorization: Bearer $CLAIMHOUSE_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "url": "https://hooks.example.com/claimhouse",
  "description": "Billing system",
  "event_types": [
    "eligibility.completed"
  ]
}'

Example response: 200

JSON
{
  "id": "whe_01JM000000E008000000000021",
  "object": "webhook_endpoint",
  "url": "https://hooks.example.com/claimhouse",
  "description": "Billing system",
  "event_types": [
    "eligibility.completed"
  ],
  "status": "enabled",
  "mode": "test",
  "created_at": "2026-03-10T15:00:00.000000+00:00",
  "secret": "whsec_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEE",
  "secret_available": true
}