Catalog Webhooks
Create a catalog webhook endpoint
Validates DNS and permits only public HTTPS destinations outside local development.
POST
cURL
Save the signing secret
The201 response includes secret exactly once. Store it securely before discarding the response. List and update operations never return it again.
- Production destinations must use public HTTPS. Lasso validates DNS and rejects local, private, and otherwise unsafe targets.
eventsmust contain at least one unique supported event.nameis optional for API clients and defaults to the destination hostname.
Examples
Example response
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
application/json
Maximum string length:
2048Minimum array length:
1Available options:
product.created, product.updated, product.deleted, attribute.created, attribute.updated, attribute.deleted Optional for API clients; defaults to the destination hostname. The dashboard requires it.
Required string length:
1 - 120Maximum string length:
500Response
Endpoint plus its one-time signing secret
Required string length:
1 - 120HTTPS public destination. HTTP localhost is accepted only by local development servers.
Minimum array length:
1Available options:
product.created, product.updated, product.deleted, attribute.created, attribute.updated, attribute.deleted One-time signing secret. It is never returned by later reads or updates.
Maximum string length:
500
