Delete a webhook
Authentication
Path parameters
UUID of the outbound webhook. It must belong to the authenticated workspace; an id from another workspace answers 404, exactly like an unknown one. Returned as id by GET /api/webhooks.
UUID of the outbound webhook. It must belong to the authenticated workspace; an id from another workspace answers 404, exactly like an unknown one. Returned as id by GET /api/webhooks.
Deletes the webhook. It stops receiving events immediately, and any delivery or retry already
queued for it is dropped without being sent. The webhook disappears from GET /api/webhooks and
its delivery log can no longer be read. There is no undelete: create a new webhook, which gets a
new secret.
Side effects. Marks the webhook deleted and inactive. Written to the audit log as webhook.delete.
Idempotency. Safe to retry. A repeated call returns 404 Webhook not found, which you can treat
as success.
Webhook events. Emits audit.log_recorded to webhooks subscribed to it. See Webhooks.
Access
full. Human users need the owner or admin role.webhook plan feature. Every plan includes it today, so this gate currently refuses nobody.Workspace API key: jl_ followed by 64 lowercase hex characters, created by the workspace owner in the
dashboard (Settings → API Keys) and sent as Authorization: Bearer jl_.... The plaintext is shown once,
at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys.
Operations restricted to admins or owners reject keys without the full scope with 403, and say so in
their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret —
that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds.
See Authentication.