curl --request POST \
--url https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'checkfu-version: <checkfu-version>' \
--data '
{
"webhook_source_id": "<string>",
"connection_id": "<string>",
"config": {
"provider": "<string>",
"resource": {
"resource_type": "<string>",
"external_id": "<string>"
},
"event_types": [
"<string>"
]
}
}
'import requests
url = "https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations"
payload = {
"webhook_source_id": "<string>",
"connection_id": "<string>",
"config": {
"provider": "<string>",
"resource": {
"resource_type": "<string>",
"external_id": "<string>"
},
"event_types": ["<string>"]
}
}
headers = {
"checkfu-version": "<checkfu-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'checkfu-version': '<checkfu-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
webhook_source_id: '<string>',
connection_id: '<string>',
config: {
provider: '<string>',
resource: {resource_type: '<string>', external_id: '<string>'},
event_types: ['<string>']
}
})
};
fetch('https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'webhook_source_id' => '<string>',
'connection_id' => '<string>',
'config' => [
'provider' => '<string>',
'resource' => [
'resource_type' => '<string>',
'external_id' => '<string>'
],
'event_types' => [
'<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"checkfu-version: <checkfu-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations"
payload := strings.NewReader("{\n \"webhook_source_id\": \"<string>\",\n \"connection_id\": \"<string>\",\n \"config\": {\n \"provider\": \"<string>\",\n \"resource\": {\n \"resource_type\": \"<string>\",\n \"external_id\": \"<string>\"\n },\n \"event_types\": [\n \"<string>\"\n ]\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations")
.header("checkfu-version", "<checkfu-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"webhook_source_id\": \"<string>\",\n \"connection_id\": \"<string>\",\n \"config\": {\n \"provider\": \"<string>\",\n \"resource\": {\n \"resource_type\": \"<string>\",\n \"external_id\": \"<string>\"\n },\n \"event_types\": [\n \"<string>\"\n ]\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"webhook_source_id\": \"<string>\",\n \"connection_id\": \"<string>\",\n \"config\": {\n \"provider\": \"<string>\",\n \"resource\": {\n \"resource_type\": \"<string>\",\n \"external_id\": \"<string>\"\n },\n \"event_types\": [\n \"<string>\"\n ]\n }\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"workspace_id": "<string>",
"automation_id": "<string>",
"webhook_source_id": "<string>",
"connection_id": "<string>",
"callback_key": "<string>",
"config": {
"provider": "<string>",
"resource": {
"resource_type": "<string>",
"external_id": "<string>"
},
"event_types": [
"<string>"
]
},
"config_fingerprint": "<string>",
"status": "pending",
"external_id": "<string>",
"claim": {
"epoch": 1,
"operation": "create",
"callback_key": "<string>",
"config_fingerprint": "<string>",
"expires_at": "<string>"
},
"last_verified_at": "<string>",
"last_delivery_at": "<string>",
"last_error": {
"code": "<string>",
"at": "<string>"
},
"version": 1,
"created_at": "<string>",
"updated_at": "<string>"
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.not_found",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-not-found"
}
}{
"error": {
"type": "validation.conflict",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-conflict"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}Create a managed provider webhook registration
Mint a ProviderWebhookRegistration for one Automation WebhookSource: persist the desired config and fingerprint, place the verification secret in CredentialCustody, claim the external create, call the provider adapter, and adopt only an exact callback key plus config fingerprint. Secrets never appear in the registration or this response. Accepts an optional Idempotency-Key.
Checkfu support posture: alpha; hosted. Required evidence journey: automation-firing. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.
curl --request POST \
--url https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'checkfu-version: <checkfu-version>' \
--data '
{
"webhook_source_id": "<string>",
"connection_id": "<string>",
"config": {
"provider": "<string>",
"resource": {
"resource_type": "<string>",
"external_id": "<string>"
},
"event_types": [
"<string>"
]
}
}
'import requests
url = "https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations"
payload = {
"webhook_source_id": "<string>",
"connection_id": "<string>",
"config": {
"provider": "<string>",
"resource": {
"resource_type": "<string>",
"external_id": "<string>"
},
"event_types": ["<string>"]
}
}
headers = {
"checkfu-version": "<checkfu-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'checkfu-version': '<checkfu-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
webhook_source_id: '<string>',
connection_id: '<string>',
config: {
provider: '<string>',
resource: {resource_type: '<string>', external_id: '<string>'},
event_types: ['<string>']
}
})
};
fetch('https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'webhook_source_id' => '<string>',
'connection_id' => '<string>',
'config' => [
'provider' => '<string>',
'resource' => [
'resource_type' => '<string>',
'external_id' => '<string>'
],
'event_types' => [
'<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"checkfu-version: <checkfu-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations"
payload := strings.NewReader("{\n \"webhook_source_id\": \"<string>\",\n \"connection_id\": \"<string>\",\n \"config\": {\n \"provider\": \"<string>\",\n \"resource\": {\n \"resource_type\": \"<string>\",\n \"external_id\": \"<string>\"\n },\n \"event_types\": [\n \"<string>\"\n ]\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations")
.header("checkfu-version", "<checkfu-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"webhook_source_id\": \"<string>\",\n \"connection_id\": \"<string>\",\n \"config\": {\n \"provider\": \"<string>\",\n \"resource\": {\n \"resource_type\": \"<string>\",\n \"external_id\": \"<string>\"\n },\n \"event_types\": [\n \"<string>\"\n ]\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/automations/{id}/provider-webhook-registrations")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"webhook_source_id\": \"<string>\",\n \"connection_id\": \"<string>\",\n \"config\": {\n \"provider\": \"<string>\",\n \"resource\": {\n \"resource_type\": \"<string>\",\n \"external_id\": \"<string>\"\n },\n \"event_types\": [\n \"<string>\"\n ]\n }\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"workspace_id": "<string>",
"automation_id": "<string>",
"webhook_source_id": "<string>",
"connection_id": "<string>",
"callback_key": "<string>",
"config": {
"provider": "<string>",
"resource": {
"resource_type": "<string>",
"external_id": "<string>"
},
"event_types": [
"<string>"
]
},
"config_fingerprint": "<string>",
"status": "pending",
"external_id": "<string>",
"claim": {
"epoch": 1,
"operation": "create",
"callback_key": "<string>",
"config_fingerprint": "<string>",
"expires_at": "<string>"
},
"last_verified_at": "<string>",
"last_delivery_at": "<string>",
"last_error": {
"code": "<string>",
"at": "<string>"
},
"version": 1,
"created_at": "<string>",
"updated_at": "<string>"
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.not_found",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-not-found"
}
}{
"error": {
"type": "validation.conflict",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-conflict"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
2026-08-24 255Path Parameters
^auto_[0-9a-f]{32}$Body
Response
Closed provider-side webhook lifecycle and health for one Automation and WebhookSource. Secrets never appear.
Closed provider-side webhook lifecycle and health for one Automation and WebhookSource. Secrets never appear.
^pwreg_[0-9a-f]{32}$^wrkspc_[0-9a-f]{32}$^auto_[0-9a-f]{32}$^whsrc_[0-9a-f]{32}$^conn_[0-9a-f]{32}$^pwcbk_[0-9a-f]{32}$Show child attributes
Show child attributes
^sha256:[0-9a-f]{64}$pending, active, degraded, indeterminate, revoked, deleted ^[a-z0-9](?:[a-z0-9._-]{0,93})$Show child attributes
Show child attributes
A canonical UTC ISO-8601 timestamp with millisecond precision.
24^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z$A canonical UTC ISO-8601 timestamp with millisecond precision.
24^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z$Show child attributes
Show child attributes
x > 0A canonical UTC ISO-8601 timestamp with millisecond precision.
24^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z$A canonical UTC ISO-8601 timestamp with millisecond precision.
24^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z$