Add a webhook
Points events at a URL of yours. Deliveries sign with material derived from the Median key that made the request, or the newest one for an OAuth token, so adding an endpoint creates no new credential. HTTPS on a public address only: localhost, private addresses and URLs with credentials answer invalid_url.
POST
/webhooksAuthorization
AuthorizationBearer token · headerrequired`MEDIAN_KEY` from Settings under API, or an MCP OAuth access token. A key acts as the organization; a token acts as the person who approved it.
Request body
requiredapplication/jsonurlstringrequiredmax length 512
eventsWebhookEvent[]requiredResponses
200Created.
idstring400The request is malformed, and the message names the field.
errorobjectShow propertiesHide properties
codestringmessagestring401The bearer token is missing, revoked, or expired.
errorobjectShow propertiesHide properties
codestringmessagestring403The token's person does not hold the role this needs.
errorobjectShow propertiesHide properties
codestringmessagestring429Too many requests. Wait the seconds in `Retry-After`. Limits depend on the plan. See [rate limits](/api/errors-and-limits#rate-limits).
errorobjectShow propertiesHide properties
codestringmessagestringRequest
curl -X POST "https://api.median.sh/v1/webhooks" \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"url": "https://example.com/median/events",
"events": [
"message.created"
]
}'const response = await fetch("https://api.median.sh/v1/webhooks", {
method: "POST",
headers: {
"Authorization": "Bearer YOUR_TOKEN",
"Content-Type": "application/json"
},
body: JSON.stringify({
"url": "https://example.com/median/events",
"events": [
"message.created"
]
})
});Response
{
"id": "string"
}{
"error": {
"code": "string",
"message": "string"
}
}{
"error": {
"code": "string",
"message": "string"
}
}{
"error": {
"code": "string",
"message": "string"
}
}{
"error": {
"code": "string",
"message": "string"
}
}