Skip to main content
PATCH
/
account
/
{accountId}
/
authorization-webhook
cURL
curl --request PATCH \
  --url https://api.slash.com/account/{accountId}/authorization-webhook \
  --header 'Content-Type: application/json' \
  --header 'X-API-Key: <api-key>' \
  --data '
{
  "webhookUrl": "<string>",
  "status": "active"
}
'
{
  "webhookUrl": "<string>",
  "signingSecret": "<string>",
  "status": "active",
  "timeoutDurationMs": 123,
  "config": {
    "fallbackBehavior": "default"
  },
  "createdAt": "2023-11-07T05:31:56Z",
  "updatedAt": "2023-11-07T05:31:56Z"
}

Documentation Index

Fetch the complete documentation index at: https://docs.slash.com/llms.txt

Use this file to discover all available pages before exploring further.

Enterprise Feature: Authorization webhooks are an enterprise-only feature. Please reach out to sales@slash.com to get set up with this functionality.
The Authorization Request Event schema shows the shape of the event that is sent to the webhook.

Authorizations

X-API-Key
string
header
required

API key authentication for public API requests.

Keys come in two flavors:

  • Legal-entity-scoped keys are pinned to a single legal entity. Minted via the dashboard under a specific entity; every request acts on that entity.
  • User-scoped keys are pinned to a user and span every legal entity that user has access to. Every request made with a user-scoped key (except GET /legal-entity, which lists the legal entities the user can access) must include an x-legal-entity header naming the legal entity the request is operating on. Requests without the header are rejected with 400. The authenticated user must have an active permission role on the supplied legal entity, otherwise the request is rejected with 403.

Path Parameters

accountId
string
required

Body

application/json
webhookUrl
string

The URL where authorization webhook events will be sent

status
enum<string>

Current status of the webhook

Available options:
active,
inactive
config
object

Configuration specific to the authorization webhook

Response

Authorization webhook updated successfully

webhookUrl
string
required

The URL where authorization webhook events will be sent

signingSecret
string
required

Secret used for signing webhook payloads

status
enum<string>
required

Current status of the webhook

Available options:
active,
inactive
timeoutDurationMs
integer
required

The timeout duration in milliseconds for webhook requests

config
object
required

Configuration specific to the authorization webhook

createdAt
string<date-time>
required

When the webhook was created

updatedAt
string<date-time>
required

When the webhook was last updated