Docs

Fincore · API reference · Webhooks

Update a client webhook

PATCH /v1/clients/{clientId}/webhooks/{id}
Try it ▸

Base URL https://apicore.stg.finch.lat · operationId updateClientWebhook

Updates one or more fields of a webhook owned by the client. All fields in the request body are optional, but at least one must be provided.

Authorization

bearerAuth Bearer token

JWT bearer token created from client credentials. Use the Authentication guide to generate a token before calling protected endpoints.

Path parameters

clientId string (uuid) required

Client UUID that owns the webhook.

id string (uuid) required

Webhook UUID.

Request body application/json · required

url string (uri)

New delivery URL for the webhook.

token string

New secret used to authenticate webhook delivery.

webhook_status string

New webhook lifecycle status.

ACTIVE INACTIVE
auth_client_id string

OAuth client identifier used when auth_type is OAUTH.

auth_client_secret string

OAuth client secret used when auth_type is OAUTH.

auth_url string (uri)

OAuth token endpoint used for webhook delivery authentication.

auth_scope string

OAuth scopes requested for webhook delivery authentication.

auth_audience string

OAuth audience requested for webhook delivery authentication.

Responses

200 Webhook successfully updated application/json
id string (uuid) required

Webhook configuration UUID.

clientId string (uuid) required

Client UUID that owns the webhook.

url string (uri) required

Destination URL where Monato sends webhook events.

token string

Secret configured for webhook delivery.

webhookType string required

Type of events delivered to this webhook.

MONEY_IN STATUS_UPDATE CEP REPORT REFUND
webhookStatus string required

Current webhook lifecycle status.

ACTIVE INACTIVE
createdAt string (date-time)

Timestamp when the webhook configuration was created.

updatedAt string (date-time)

Timestamp when the webhook configuration was last updated.

deletedAt string | null

Timestamp when the webhook configuration was deleted, or null.

blockedAt string | null

Timestamp when the webhook configuration was blocked, or null.

deletedBy string | null

Identifier of the actor that deleted the webhook, or null.

blockedBy string | null

Identifier of the actor that blocked the webhook, or null.

400 Webhook update request is invalid. Possible causes: malformed clientId or webhook id, empty update body, invalid URL, unsupported webhook_type, unsupported auth_type, or unsupported webhook_status. application/json
code integer required

gRPC status code mapped to HTTP.

message string required

General error message.

details array of ErrorDetail required

Detailed error causes returned by the service.

reason details[].reason string required

Machine-readable error category.

DATA_ERROR FAILED_PRECONDITION MISSING_REQUIRED_FIELDS RESOURCE_NOT_FOUND UNAUTHORIZED PERMISSION_DENIED UNIQUE_VIOLATION INTERNAL
domain details[].domain string required

Service domain that produced the error.

metadata details[].metadata object required

Additional error metadata, including the detailed message and HTTP code.

error_detail details[].metadata.error_detail string

Human-readable detail returned by the service.

http_code details[].metadata.http_code string

HTTP status code associated with this error.

error_code details[].metadata.error_code string

Optional internal error catalog code when available.

401 Missing, expired, invalid, or environment-mismatched API key or bearer token. See Authentication. application/json
code integer required

gRPC status code mapped to HTTP.

message string required

General error message.

details array of ErrorDetail required

Detailed error causes returned by the service.

reason details[].reason string required

Machine-readable error category.

DATA_ERROR FAILED_PRECONDITION MISSING_REQUIRED_FIELDS RESOURCE_NOT_FOUND UNAUTHORIZED PERMISSION_DENIED UNIQUE_VIOLATION INTERNAL
domain details[].domain string required

Service domain that produced the error.

metadata details[].metadata object required

Additional error metadata, including the detailed message and HTTP code.

error_detail details[].metadata.error_detail string

Human-readable detail returned by the service.

http_code details[].metadata.http_code string

HTTP status code associated with this error.

error_code details[].metadata.error_code string

Optional internal error catalog code when available.

404 Webhook was not found for the supplied client. application/json
code integer required

gRPC status code mapped to HTTP.

message string required

General error message.

details array of ErrorDetail required

Detailed error causes returned by the service.

reason details[].reason string required

Machine-readable error category.

DATA_ERROR FAILED_PRECONDITION MISSING_REQUIRED_FIELDS RESOURCE_NOT_FOUND UNAUTHORIZED PERMISSION_DENIED UNIQUE_VIOLATION INTERNAL
domain details[].domain string required

Service domain that produced the error.

metadata details[].metadata object required

Additional error metadata, including the detailed message and HTTP code.

error_detail details[].metadata.error_detail string

Human-readable detail returned by the service.

http_code details[].metadata.http_code string

HTTP status code associated with this error.

error_code details[].metadata.error_code string

Optional internal error catalog code when available.

This request is in the Monato · Fincore Postman collection, folder Webhooks.Download collection

Request

curl -X PATCH "https://apicore.stg.finch.lat/v1/clients/{clientId}/webhooks/{id}" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "url": "https://example.com/new-webhook",
  "webhook_status": "ACTIVE"
}'

Response

{
  "id": "29806117-2b15-4682-87f0-350e6695fe91",
  "clientId": "c2d1d1e3-3340-4170-980e-e9269bbbc551",
  "url": "https://example.com/webhook",
  "token": "secretToken0123",
  "webhookType": "MONEY_IN",
  "webhookStatus": "ACTIVE",
  "createdAt": "2025-04-03 13:40:54.056794-06:00",
  "updatedAt": "2025-04-03 13:40:54.056794-06:00",
  "deletedAt": null,
  "blockedAt": null,
  "deletedBy": null,
  "blockedBy": null
}