Create a webhook endpoint
curl --request POST \
--url https://app.sahlfinancial.com/api/v1/webhooks \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"url": "https://example.com/hooks/sahl",
"events": [
"case.created",
"case.scored"
],
"description": "Case events to the loan system"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
url: 'https://example.com/hooks/sahl',
events: ['case.created', 'case.scored'],
description: 'Case events to the loan system'
})
};
fetch('https://app.sahlfinancial.com/api/v1/webhooks', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/webhooks"
payload = {
"url": "https://example.com/hooks/sahl",
"events": ["case.created", "case.scored"],
"description": "Case events to the loan system"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "e4b7a2c9-1f6d-4d38-a5e3-7c9b0d2f8a41",
"tenant_id": "0b6f5a3e-7c1d-4e0a-9d2f-3a1c5e8b7f10",
"url": "https://example.com/hooks/sahl",
"events": "case.created,case.scored",
"is_active": true,
"description": "Case events to the loan system",
"created_at": "2026-10-07T09:14:22Z",
"updated_at": "2026-10-07T09:14:22Z",
"secret": "whsec_3f1a9c...redacted"
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"detail": {
"code": "unknown_webhook_event",
"message": "Unknown event(s): case.exploded",
"allowed": [
"case.created",
"case.scored"
]
}
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Create a webhook endpoint
Who can call it: tenant_admin, tenant_api_manager or platform_admin.
The URL must be https and resolve to a public address (checked again before every delivery). If you omit secret, Sahl generates one (whsec_...) and returns it once, in this response. How to verify the signature: see the Webhooks guide.
Auth: dashboard session (Authorization: Bearer <access token>). Not available with a partner API key.
Create a webhook endpoint
curl --request POST \
--url https://app.sahlfinancial.com/api/v1/webhooks \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"url": "https://example.com/hooks/sahl",
"events": [
"case.created",
"case.scored"
],
"description": "Case events to the loan system"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
url: 'https://example.com/hooks/sahl',
events: ['case.created', 'case.scored'],
description: 'Case events to the loan system'
})
};
fetch('https://app.sahlfinancial.com/api/v1/webhooks', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/webhooks"
payload = {
"url": "https://example.com/hooks/sahl",
"events": ["case.created", "case.scored"],
"description": "Case events to the loan system"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "e4b7a2c9-1f6d-4d38-a5e3-7c9b0d2f8a41",
"tenant_id": "0b6f5a3e-7c1d-4e0a-9d2f-3a1c5e8b7f10",
"url": "https://example.com/hooks/sahl",
"events": "case.created,case.scored",
"is_active": true,
"description": "Case events to the loan system",
"created_at": "2026-10-07T09:14:22Z",
"updated_at": "2026-10-07T09:14:22Z",
"secret": "whsec_3f1a9c...redacted"
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"detail": {
"code": "unknown_webhook_event",
"message": "Unknown event(s): case.exploded",
"allowed": [
"case.created",
"case.scored"
]
}
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Authorizations
The access token (JWT) of a signed-in console user, from POST /v1/auth/login. It lasts 30 minutes. It is not an API key: a partner API key is refused here. There is no cookie.
Body
application/json
Response
Created
Returned only at creation: carries the signing secret when Sahl made it.