cURL
curl --request POST \
--url https://api-alpha.fourvenues.com/integrations/webhook-endpoints/ \
--header 'Content-Type: application/json' \
--header 'integration_id: <api-key>' \
--header 'secret: <api-key>' \
--header 'x-api-key: <api-key>' \
--data '
{
"name": "Production endpoint",
"url": "https://example.com/webhooks/fourvenues",
"events": [
"ticket.sold",
"booking.created"
]
}
'import requests
url = "https://api-alpha.fourvenues.com/integrations/webhook-endpoints/"
payload = {
"name": "Production endpoint",
"url": "https://example.com/webhooks/fourvenues",
"events": ["ticket.sold", "booking.created"]
}
headers = {
"integration_id": "<api-key>",
"secret": "<api-key>",
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
integration_id: '<api-key>',
secret: '<api-key>',
'x-api-key': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: 'Production endpoint',
url: 'https://example.com/webhooks/fourvenues',
events: ['ticket.sold', 'booking.created']
})
};
fetch('https://api-alpha.fourvenues.com/integrations/webhook-endpoints/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api-alpha.fourvenues.com/integrations/webhook-endpoints/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Production endpoint',
'url' => 'https://example.com/webhooks/fourvenues',
'events' => [
'ticket.sold',
'booking.created'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"integration_id: <api-key>",
"secret: <api-key>",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api-alpha.fourvenues.com/integrations/webhook-endpoints/"
payload := strings.NewReader("{\n \"name\": \"Production endpoint\",\n \"url\": \"https://example.com/webhooks/fourvenues\",\n \"events\": [\n \"ticket.sold\",\n \"booking.created\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("integration_id", "<api-key>")
req.Header.Add("secret", "<api-key>")
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api-alpha.fourvenues.com/integrations/webhook-endpoints/")
.header("integration_id", "<api-key>")
.header("secret", "<api-key>")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Production endpoint\",\n \"url\": \"https://example.com/webhooks/fourvenues\",\n \"events\": [\n \"ticket.sold\",\n \"booking.created\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api-alpha.fourvenues.com/integrations/webhook-endpoints/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["integration_id"] = '<api-key>'
request["secret"] = '<api-key>'
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Production endpoint\",\n \"url\": \"https://example.com/webhooks/fourvenues\",\n \"events\": [\n \"ticket.sold\",\n \"booking.created\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"data": {
"id": "we_4gr63f00xkq01i1d8jh5ohuzaZhvoE",
"organization_id": "org_4gr63f00xkq01i1d8jh5ohuzaZhvoE",
"name": "Production endpoint",
"url": "https://example.com/webhooks/fourvenues",
"events": [
"ticket.sold",
"booking.created"
],
"status": "active",
"sign_secret": "whsec_9f1c2a7e4b6d4a0e8c3f2d1b5a6e7c8d"
}
}Webhook Endpoints
Post webhook endpoints
Creates a webhook subscription for the organization. `events` is deduplicated automatically. `sign_secret` is shown only once — store it now, it cannot be retrieved later. There is no rotation: if you lose it, create a new endpoint. <br><br>Outbound webhook contract: every webhook is an HTTP POST to the endpoint URL with a minimal, stable JSON body (`id`, `event`, `resource_type`, `resource_id`, `created_at` — see the `WebhookEventPayload` schema). It is a change ping: fetch the resource details from this API using `resource_id`. <br><br>Signature: each request carries `X-Webhook-Id` (the delivery id) and `X-Webhook-Signature: t=<unix seconds>,v1=<hex>`, where `<hex>` is the HMAC-SHA256 of `"<t>.<raw body>"` keyed with `sign_secret`. Recompute it over the raw body and compare with a constant-time equality check; reject stale timestamps to prevent replays. <br><br>Delivery semantics: any 2xx acknowledges the delivery (10 s timeout, redirects are not followed). Anything else is retried with exponential backoff and jitter, up to 20 attempts over ~72 h. Delivery is at-least-once and unordered: deduplicate by payload `id`.
POST
/
webhook-endpoints
/
cURL
curl --request POST \
--url https://api-alpha.fourvenues.com/integrations/webhook-endpoints/ \
--header 'Content-Type: application/json' \
--header 'integration_id: <api-key>' \
--header 'secret: <api-key>' \
--header 'x-api-key: <api-key>' \
--data '
{
"name": "Production endpoint",
"url": "https://example.com/webhooks/fourvenues",
"events": [
"ticket.sold",
"booking.created"
]
}
'import requests
url = "https://api-alpha.fourvenues.com/integrations/webhook-endpoints/"
payload = {
"name": "Production endpoint",
"url": "https://example.com/webhooks/fourvenues",
"events": ["ticket.sold", "booking.created"]
}
headers = {
"integration_id": "<api-key>",
"secret": "<api-key>",
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
integration_id: '<api-key>',
secret: '<api-key>',
'x-api-key': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: 'Production endpoint',
url: 'https://example.com/webhooks/fourvenues',
events: ['ticket.sold', 'booking.created']
})
};
fetch('https://api-alpha.fourvenues.com/integrations/webhook-endpoints/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api-alpha.fourvenues.com/integrations/webhook-endpoints/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Production endpoint',
'url' => 'https://example.com/webhooks/fourvenues',
'events' => [
'ticket.sold',
'booking.created'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"integration_id: <api-key>",
"secret: <api-key>",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api-alpha.fourvenues.com/integrations/webhook-endpoints/"
payload := strings.NewReader("{\n \"name\": \"Production endpoint\",\n \"url\": \"https://example.com/webhooks/fourvenues\",\n \"events\": [\n \"ticket.sold\",\n \"booking.created\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("integration_id", "<api-key>")
req.Header.Add("secret", "<api-key>")
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api-alpha.fourvenues.com/integrations/webhook-endpoints/")
.header("integration_id", "<api-key>")
.header("secret", "<api-key>")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Production endpoint\",\n \"url\": \"https://example.com/webhooks/fourvenues\",\n \"events\": [\n \"ticket.sold\",\n \"booking.created\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api-alpha.fourvenues.com/integrations/webhook-endpoints/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["integration_id"] = '<api-key>'
request["secret"] = '<api-key>'
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Production endpoint\",\n \"url\": \"https://example.com/webhooks/fourvenues\",\n \"events\": [\n \"ticket.sold\",\n \"booking.created\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"data": {
"id": "we_4gr63f00xkq01i1d8jh5ohuzaZhvoE",
"organization_id": "org_4gr63f00xkq01i1d8jh5ohuzaZhvoE",
"name": "Production endpoint",
"url": "https://example.com/webhooks/fourvenues",
"events": [
"ticket.sold",
"booking.created"
],
"status": "active",
"sign_secret": "whsec_9f1c2a7e4b6d4a0e8c3f2d1b5a6e7c8d"
}
}Authorizations
Identifier of the integration (Auth v1)
Secret of the organization (Auth v1)
API key (Auth v2)
Body
application/json
Webhook endpoint to create.
Name of the webhook endpoint.
Example:
"Production endpoint"
HTTPS destination URL of the webhook endpoint.
Example:
"https://example.com/webhooks/fourvenues"
Event types to subscribe to. Deduplicated automatically. At least 1 required.
Minimum array length:
1Available options:
ticket.sold, ticket.refunded, ticket.cancelled, ticket.created, payment.completed, booking.created, booking.changed, booking.cancelled, booking.payment_received Example:
["ticket.sold", "booking.created"]