import { Autumn } from 'autumn-js'
const autumn = new Autumn()
const result = await autumn.webhooks.create({
id: "billing",
url: "https://example.com/webhooks/autumn",
events: [
"billing.updated",
"invoice.finalized",
],
description: "Plan changes and invoices",
});from autumn_sdk import Autumn
autumn = Autumn(secret_key="am_sk_test...")
res = autumn.webhooks.create(
id="billing",
url="https://example.com/webhooks/autumn",
events=[
"billing.updated",
"invoice.finalized",
],
description="Plan changes and invoices",
)curl --request POST \
--url https://api.useautumn.com/v1/webhooks.create \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'x-api-version: <x-api-version>' \
--data '
{
"id": "billing",
"url": "https://example.com/webhooks/autumn",
"events": [
"billing.updated",
"invoice.finalized"
],
"description": "Plan changes and invoices"
}
'{
"id": "billing",
"url": "https://example.com/webhooks/autumn",
"events": [
"billing.updated",
"invoice.finalized"
],
"description": "Plan changes and invoices",
"disabled": false,
"created_at": 1781113864000,
"updated_at": 1781113864000,
"secret": "whsec_abc123"
}
Create Webhook
Creates a webhook: a URL Autumn sends the listed events to, in the environment of the calling key. You choose the id, and it can’t be changed later. Returns the signing secret once, in this response — store it, it cannot be read back.
import { Autumn } from 'autumn-js'
const autumn = new Autumn()
const result = await autumn.webhooks.create({
id: "billing",
url: "https://example.com/webhooks/autumn",
events: [
"billing.updated",
"invoice.finalized",
],
description: "Plan changes and invoices",
});from autumn_sdk import Autumn
autumn = Autumn(secret_key="am_sk_test...")
res = autumn.webhooks.create(
id="billing",
url="https://example.com/webhooks/autumn",
events=[
"billing.updated",
"invoice.finalized",
],
description="Plan changes and invoices",
)curl --request POST \
--url https://api.useautumn.com/v1/webhooks.create \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'x-api-version: <x-api-version>' \
--data '
{
"id": "billing",
"url": "https://example.com/webhooks/autumn",
"events": [
"billing.updated",
"invoice.finalized"
],
"description": "Plan changes and invoices"
}
'{
"id": "billing",
"url": "https://example.com/webhooks/autumn",
"events": [
"billing.updated",
"invoice.finalized"
],
"description": "Plan changes and invoices",
"disabled": false,
"created_at": 1781113864000,
"updated_at": 1781113864000,
"secret": "whsec_abc123"
}
Body Parameters
Response
{
"id": "billing",
"url": "https://example.com/webhooks/autumn",
"events": [
"billing.updated",
"invoice.finalized"
],
"description": "Plan changes and invoices",
"disabled": false,
"created_at": 1781113864000,
"updated_at": 1781113864000,
"secret": "whsec_abc123"
}
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
Body
Your ID for the webhook: letters, digits, - and _. It can't be changed after creation.
1 - 256^[a-zA-Z0-9_-]+$The https URL Autumn sends events to. Localhost and private-network addresses are rejected; tunnels such as ngrok work.
^[Hh][Tt][Tt][Pp][Ss]:\/\/The events sent to this webhook. At least one. vercel.* events can't be mixed with other events.
1An event type the webhook receives.
customer.products.updated, customer.threshold_reached, balances.usage_alert_triggered, balances.limit_reached, billing.auto_topup_failed, billing.auto_topup_succeeded, billing.updated, invoice.finalized, vercel.resources.deleted, vercel.resources.provisioned, vercel.resources.rotate_secrets, vercel.webhooks.event A note for your own reference.
When true, no events are sent to the webhook.
Response
OK
The webhook's ID. Webhooks made in the dashboard show their ep_… ID.
The URL Autumn sends events to.
A note for your own reference.
The events sent to this webhook, as WebhookEventType names; a type newer than your client is returned as-is. Empty only for a webhook made in the dashboard that receives every event.
When true, no events are sent to the webhook.
When the webhook was created, ms since epoch.
When the webhook was last changed, ms since epoch.
The webhook's signing secret. Shown once, here: store it before you discard the response.