Documentation
The API is small on purpose. These are the pages that cover it, in the order most people need them.
In short
- Start with the walkthrough: account, endpoint, first delivery.
- Every dashboard action is an API call with the same permissions.
- Signature verification is fifteen lines — the guide has it in full.
Start here
Your first delivery
Account, destination, publish, and the timeline that shows it arriving.
Consumers
Verifying signatures
The three headers, the verification function, and the mistake everyone makes once.
Reliability
Retries and idempotency
The schedule, what a retry preserves, and how a consumer avoids double-processing.
Operations
Dead letters and recovery
What happens when the schedule is spent, and the two buttons that fix it.
Inbound
Platform guides
Receiving verified webhooks from fifteen providers.
Everything
All guides
Testing, debugging, egress safety, and the rest.
API surface
Authentication is a bearer token: an API key for machines, a session for the dashboard.
| Endpoint | What it does |
|---|---|
POST /v1/events | Publish an event. Answers 202 once it is stored. Optional attributes and metrics make it chart on a dashboard |
POST /v1/events/batch | Publish several; each item is judged on its own |
GET /v1/events | The event log, filterable by type |
GET /v1/events/{id}/attempts | The delivery timeline for one event |
POST /v1/events/{id}/replay | Send an event again |
POST /v1/events/replay-missing | Repair a gap: re-queue events with no attempt |
POST /v1/endpoints | Create a destination. The signing secret is returned once — as is the ed25519 private key, if you asked for signing_scheme: "ed25519" |
PATCH /v1/endpoints/{id} | Change the URL, the retry schedule, the filter, the transformation or the signing scheme |
POST /v1/portal-links | Mint a consumer portal grant. embed: true plus a brand returns an iframe snippet with your logo and colour; manage: true lets the holder move their destination, rotate their key and pause deliveries; consumer_id plus create: true lets them add endpoints of their own — and every later link for that consumer sees them |
POST /v1/portal/endpoints | Create an endpoint from inside the portal, under a consumer grant. A URL, event types and a description — narrower than the operator surface, deliberately |
GET /v1/poll/{id} | A polling destination, read from a cursor — for a consumer with no public URL. Authenticated with a portal grant |
POST /v1/endpoints/{id}/rotate-secret | Rotate with an overlap window |
POST /v1/endpoints/{id}/recover | Resume a disabled destination and replay its dead letters |
GET /v1/endpoints/{id}/health | Success rate, latency percentiles, consecutive failures |
POST /v1/sources | Create a verified inbound source |
POST /ingest/{id} | Where the third-party provider posts |
GET /v1/dlq · POST /v1/dlq/replay | Inspect and drain dead letters |
GET /v1/stats · GET /v1/usage | Volumes and billable units |
POST /v1/keys | Mint a scoped key. Never more powerful than the key that created it |
/v1/members | Team management |
/v1/private-repos | Private Repo: register a repository under a hash, report a checkpoint manifest, read history and machine health. Opaque ids and counts only — no path, no commit message, no code ever reaches these routes |
/v1/ai-spend | AI spend by model, feature tag, ledger or mapped person, and the remaining prepaid gateway balance. Read-only |
Errors are RFC 9457 problem documents: a type, a title, a status and a readable detail. A resource that belongs to another tenant is reported as not found.
Event types the connectors emit
A pull connector reports what the provider reports: settled aggregates, never one row per call. The AI ones are worth naming because money and tokens are deliberately separate.
| Event type | What it carries |
|---|---|
llm.usage_reported | Tokens for one settled (bucket, model): input, output, cached, reasoning, requests. No cost — summing a per-model cost column would multiply the bill |
llm.cost_reported | The money, on its own event. sum(cost_usd) is the bill |
llm.credits_reported | Remaining prepaid balance on a unified-billing gateway. A level, not a flow — a balance that empties strands production silently |
The ai-gateway source reads a unified-billing gateway’s reporting
API, so spend that left the provider’s own ledger is still visible. Its events always declare
provider: "ai-gateway" with the upstream vendor as upstream_provider:
a customer running both ledgers can never have one request counted twice. Aggregates only —
request logs contain prompts and are never read.
For agents
HookGet ships an MCP server — the same API behind 57 tools, so an assistant can publish an event, read a delivery timeline, diagnose an endpoint, read what AI cost by feature, or repair a gap. Operations that re-send real traffic require an explicit confirmation argument rather than a polite label.
Start delivering webhooks today
Point your webhooks at HookGet and watch the first delivery arrive, signed, in under a minute.
Create a free account Try the free webhook tester
10,000 deliveries a month free, no credit card. The free tier blocks rather than bills, so trying it cannot produce an invoice.