Update Webhook
Base URL https://dev-api.finco.lat · operationId updateWebhook
Updates an existing webhook configuration. The webhook will be deactivated and a new activation test will be sent. The webhook will only become active again if the new endpoint responds successfully to the activation test.
Authorization
X-Client-IdClient API key (32-character hex) obtained from client creation process. Must be used with X-Signature and X-Timestamp headers for HMAC authentication.
X-SignatureHMAC-SHA256 signature generated using your api_secret. Format: HMAC-SHA256(timestamp + "." + requestBody, api_secret)
X-TimestampUnix timestamp (seconds since epoch) when the request was created. Used in HMAC signature generation to prevent replay attacks.
Request body application/json · required
id integer requiredWebhook configuration ID to update
endpoint_url string (uri) requiredNew webhook endpoint URL
Responses
200 Webhook updated successfully and activation test initiated application/json
event string Event type identifier
webhook.updated id integer Webhook configuration ID
endpoint_url string (uri) Updated webhook endpoint URL
secret_token string 64-character hexadecimal secret token (unchanged)
updated_at string (date-time) ISO 8601 timestamp of last update
400 Bad Request - Invalid webhook configuration application/json
event string Event type identifier
webhook.failed errors object | string | array of string 401 Unauthorized - Invalid or missing authentication application/json
error string Error message
404 Webhook configuration not found application/json
event string Event type identifier
webhook.failed errors object | string | array of string Request
# SIGNATURE = HMAC-SHA256(TIMESTAMP + "." + request body, api_secret)
curl -X PUT "https://dev-api.finco.lat/api/v1/cash/webhooks/active" \
-H "X-Client-Id: $CLIENT_ID" \
-H "X-Signature: $SIGNATURE" \
-H "X-Timestamp: $TIMESTAMP" \
-H "Content-Type: application/json" \
-d '{
"id": 456,
"endpoint_url": "https://new-webhook-endpoint.com/webhooks"
}'import crypto from "node:crypto";
const body = JSON.stringify({
"id": 456,
"endpoint_url": "https://new-webhook-endpoint.com/webhooks"
});
const TIMESTAMP = Math.floor(Date.now() / 1000).toString();
const SIGNATURE = crypto.createHmac("sha256", API_SECRET).update(TIMESTAMP + "." + body).digest("hex");
const res = await fetch("https://dev-api.finco.lat/api/v1/cash/webhooks/active", {
method: "PUT",
headers: {
"X-Client-Id": CLIENT_ID,
"X-Signature": SIGNATURE,
"X-Timestamp": TIMESTAMP,
"Content-Type": "application/json",
},
body,
});
const data = await res.json();import requests
import hashlib
import hmac
import json
import time
payload = {
"id": 456,
"endpoint_url": "https://new-webhook-endpoint.com/webhooks"
}
body = json.dumps(payload, separators=(",", ":"))
TIMESTAMP = str(int(time.time()))
SIGNATURE = hmac.new(API_SECRET.encode(), f"{TIMESTAMP}.{body}".encode(), hashlib.sha256).hexdigest()
res = requests.put(
"https://dev-api.finco.lat/api/v1/cash/webhooks/active",
headers={
"X-Client-Id": CLIENT_ID,
"X-Signature": SIGNATURE,
"X-Timestamp": TIMESTAMP,
"Content-Type": "application/json",
},
data=body,
)
data = res.json()Response
{
"event": "webhook.updated",
"id": 456,
"endpoint_url": "https://new-webhook-endpoint.com/webhooks",
"secret_token": "644530cd9b0b431e61b8c6c656d17c77481047215a3ac66db71a7ad490397f7c",
"updated_at": "2025-01-15T11:30:00Z"
}{
"event": "webhook.failed",
"errors": {
"endpoint_url": [
"must be a valid URL"
]
}
}{
"error": "Unauthorized"
}{
"event": "webhook.failed",
"errors": "Webhook config not found"
}