Skip to main content
POST
cURL

Save the signing secret

The 201 response includes secret exactly once. Store it securely before discarding the response. List and update operations never return it again.
  • Production destinations must use public HTTPS. Lasso validates DNS and rejects local, private, and otherwise unsafe targets.
  • events must contain at least one unique supported event.
  • name is optional for API clients and defaults to the destination hostname.
Verify signatures using the raw request body. See Catalog webhooks for headers, signature verification, retries, and payloads.

Examples

Example response

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
url
string<uri>
required
Maximum string length: 2048
events
enum<string>[]
required
Minimum array length: 1
Available options:
product.created,
product.updated,
product.deleted,
attribute.created,
attribute.updated,
attribute.deleted
name
string

Optional for API clients; defaults to the destination hostname. The dashboard requires it.

Required string length: 1 - 120
description
string | null
Maximum string length: 500

Response

Endpoint plus its one-time signing secret

id
string<uuid>
required
company_id
string<uuid>
required
name
string
required
Required string length: 1 - 120
url
string<uri>
required

HTTPS public destination. HTTP localhost is accepted only by local development servers.

events
enum<string>[]
required
Minimum array length: 1
Available options:
product.created,
product.updated,
product.deleted,
attribute.created,
attribute.updated,
attribute.deleted
enabled
boolean
required
created_at
string<date-time>
required
updated_at
string<date-time>
required
secret
string
required

One-time signing secret. It is never returned by later reads or updates.

description
string | null
Maximum string length: 500