Docs

Cash · API reference

Update Webhook

PUT /api/v1/cash/webhooks/active
Try it ▸

Base URL https://dev-api.finco.lat · operationId updateWebhook

Updates an existing webhook configuration. The webhook will be deactivated and a new activation test will be sent. The webhook will only become active again if the new endpoint responds successfully to the activation test.

Authorization

ClientAuth API key in header X-Client-Id

Client API key (32-character hex) obtained from client creation process. Must be used with X-Signature and X-Timestamp headers for HMAC authentication.

HMACSignature API key in header X-Signature

HMAC-SHA256 signature generated using your api_secret. Format: HMAC-SHA256(timestamp + "." + requestBody, api_secret)

Timestamp API key in header X-Timestamp

Unix timestamp (seconds since epoch) when the request was created. Used in HMAC signature generation to prevent replay attacks.

Request body application/json · required

id integer required

Webhook configuration ID to update

endpoint_url string (uri) required

New webhook endpoint URL

Responses

200 Webhook updated successfully and activation test initiated application/json
event string

Event type identifier

webhook.updated
id integer

Webhook configuration ID

endpoint_url string (uri)

Updated webhook endpoint URL

secret_token string

64-character hexadecimal secret token (unchanged)

updated_at string (date-time)

ISO 8601 timestamp of last update

400 Bad Request - Invalid webhook configuration application/json
event string

Event type identifier

webhook.failed
errors object | string | array of string
401 Unauthorized - Invalid or missing authentication application/json
error string

Error message

404 Webhook configuration not found application/json
event string

Event type identifier

webhook.failed
errors object | string | array of string
This request is in the Monato · Cash Postman collection.Download collection

Request

# SIGNATURE = HMAC-SHA256(TIMESTAMP + "." + request body, api_secret)
curl -X PUT "https://dev-api.finco.lat/api/v1/cash/webhooks/active" \
  -H "X-Client-Id: $CLIENT_ID" \
  -H "X-Signature: $SIGNATURE" \
  -H "X-Timestamp: $TIMESTAMP" \
  -H "Content-Type: application/json" \
  -d '{
  "id": 456,
  "endpoint_url": "https://new-webhook-endpoint.com/webhooks"
}'

Response

{
  "event": "webhook.updated",
  "id": 456,
  "endpoint_url": "https://new-webhook-endpoint.com/webhooks",
  "secret_token": "644530cd9b0b431e61b8c6c656d17c77481047215a3ac66db71a7ad490397f7c",
  "updated_at": "2025-01-15T11:30:00Z"
}