> ## Documentation Index
> Fetch the complete documentation index at: https://chainpatrol.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure Webhook

> Create and configure a webhook for an organization to receive real-time notifications for asset status updates and threat detections. Requires a valid API key with access to the specified organization.

## Overview

Create and configure a webhook for an organization to receive real-time notifications
for asset status updates and threat detections. Requires an API key with access to the
specified organization.

<Info>
  See the [Webhooks integration guide](/docs/integration/webhooks) for the payload shapes and
  delivery behavior.
</Info>


## OpenAPI

````yaml POST /webhook/config
openapi: 3.0.3
info:
  title: ChainPatrol External API - OpenAPI 3.0
  description: ChainPatrol External API documentation
  version: 2.0.0
servers:
  - url: https://app.chainpatrol.io/api/v2
security: []
tags:
  - name: asset
  - name: report
externalDocs:
  url: https://chainpatrol.com/docs
paths:
  /webhook/config:
    post:
      tags:
        - webhook
      summary: Configure webhook for organization
      description: >-
        Create and configure a webhook for an organization to receive real-time
        notifications for asset status updates and threat detections. Requires a
        valid API key with access to the specified organization.
      operationId: webhookConfig
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                organizationSlug:
                  type: string
                  description: Organization slug to configure webhooks for
                subscriberUrl:
                  type: string
                  format: uri
                  description: HTTPS URL where webhook events will be delivered
                description:
                  type: string
                  description: Optional description for the webhook
                active:
                  type: boolean
                  default: true
                  description: Whether the webhook should be active
                triggers:
                  type: array
                  items:
                    type: string
                    enum:
                      - DEBUG_TEST
                      - ASSET_STATUS_UPDATED
                      - ORGANIZATION_THREAT_DETECTION_ADDED
                      - ASSET_STATUS_ESCALATED
                  minItems: 1
                  description: Array of webhook events to subscribe to
              required:
                - organizationSlug
                - subscriberUrl
                - triggers
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: number
                    description: The ID of the created webhook
                  subscriberUrl:
                    type: string
                    description: The webhook URL
                  description:
                    type: string
                    nullable: true
                    description: Webhook description
                  active:
                    type: boolean
                    description: Whether the webhook is active
                  secret:
                    type: string
                    description: Webhook signing secret for verifying payloads
                  triggers:
                    type: array
                    items:
                      type: string
                      enum:
                        - DEBUG_TEST
                        - ASSET_STATUS_UPDATED
                        - ORGANIZATION_THREAT_DETECTION_ADDED
                        - ASSET_STATUS_ESCALATED
                    description: Array of subscribed webhook events
                  organizationSlug:
                    type: string
                    description: Organization slug this webhook belongs to
                required:
                  - id
                  - subscriberUrl
                  - description
                  - active
                  - secret
                  - triggers
                  - organizationSlug
        '400':
          description: Invalid input data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.BAD_REQUEST'
        '401':
          description: Authorization not provided
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.UNAUTHORIZED'
        '403':
          description: Insufficient access
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.FORBIDDEN'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.INTERNAL_SERVER_ERROR'
      security:
        - ApiKey: []
components:
  schemas:
    error.BAD_REQUEST:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Invalid input data
        code:
          type: string
          description: The error code
          example: BAD_REQUEST
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Invalid input data error (400)
      description: The error information
      example:
        code: BAD_REQUEST
        message: Invalid input data
        issues: []
    error.UNAUTHORIZED:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Authorization not provided
        code:
          type: string
          description: The error code
          example: UNAUTHORIZED
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Authorization not provided error (401)
      description: The error information
      example:
        code: UNAUTHORIZED
        message: Authorization not provided
        issues: []
    error.FORBIDDEN:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Insufficient access
        code:
          type: string
          description: The error code
          example: FORBIDDEN
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Insufficient access error (403)
      description: The error information
      example:
        code: FORBIDDEN
        message: Insufficient access
        issues: []
    error.INTERNAL_SERVER_ERROR:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Internal server error
        code:
          type: string
          description: The error code
          example: INTERNAL_SERVER_ERROR
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Internal server error error (500)
      description: The error information
      example:
        code: INTERNAL_SERVER_ERROR
        message: Internal server error
        issues: []
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: X-API-KEY
      description: >-
        Your API key. This is required by most endpoints to access our API
        programatically. Reach out to us at
        [support@chainpatrol.io](mailto:support@chainpatrol.io?subject=Re:%20API%20Key%20for%20SDK&body=Company:%20%0AName:%20%0APurpose:%20)
        to get an API key for your use.

````