Sign inGet Started

Update a webhook endpoint

PATCH
/v1/webhooks/{webhook_id}
const endpoint = await bird.webhooks.update("whk_01krdgeqcxet5s7t44vh8rt9mg", {
  events: ["email.delivered"],
});
console.log(endpoint.events);
Response200
{
  "id": "whk_01krdgeqcxet5s7t44vh8rt9mg",
  "url": "https://example.com/webhook",
  "description": "Production webhook endpoint",
  "filter": null,
  "events": [
    "email.delivered",
    "email.bounced"
  ],
  "status": "active",
  "destination": {
    "type": "webhook"
  },
  "created_at": "2026-05-20T09:14:52Z",
  "updated_at": "2026-05-25T16:42:01Z"
}

Updates the webhook endpoint. Only the fields you send change: events replaces the whole subscription set, and status pauses or re-enables delivery.

The 200 response is the updated endpoint. Invalid input (a non-HTTPS or non-public url, an event type outside the catalog) returns a 422.

Parameters

webhook_idstring

ID of the webhook endpoint (whk_ prefix), as returned when it was created.

Request Payload

url
string

Replacement delivery URL. Same rules as at creation: HTTPS, at most 2048 characters, and the host must be publicly reachable (private, loopback, and link-local addresses return a 422). Omit to keep the current URL. A connector endpoint's URL comes from its connector and cannot be replaced: any value returns a 422.

description
string

Human-readable label for this endpoint, up to 256 characters.

filter
nullable object

Replace the mailbox scope. Omit to keep it, or send null to include all resources. Scoped endpoints accept only email_mailbox events.

Show child parameters
filter.mailbox_id
string
required

Mailbox to receive events for. Must belong to this workspace; a mailbox outside it returns 422.

events
array of string

Replaces all event subscriptions with this list. Omit to keep the current set. Types outside the event catalog return a 422.

credentials
object

New values for a connector destination's secret fields, merged over the stored ones: a key given replaces that field and an omitted key keeps its value. The merged set is checked as at creation, and the next delivery, retries included, uses it. On an endpoint without a connector destination this returns a 422. Omit to keep the current credentials.

status
string

paused stops all deliveries; active re-enables a paused endpoint. Omit to leave the status unchanged. Events that fire while paused are not delivered and a replay cannot recover them, because they were never attempted; after re-enabling, Replay failed deliveries reaches only the deliveries that failed before the pause. A degraded endpoint cannot be reset through this field: it returns to active automatically once deliveries succeed again.

Possible values: active, paused

Response Payload

id
string
required

Unique identifier for the endpoint (whk_ prefix). Accepted as webhook_id by every /v1/webhooks/{webhook_id} operation.

url
string
required

HTTPS URL where the API delivers events for this endpoint.

description
string

Human-readable label for the endpoint.

filter
nullable object
required

Mailbox scope configured through filter, or null.

Show child attributes
filter.mailbox_id
string
required

Mailbox to receive events for. Must belong to this workspace; a mailbox outside it returns 422.

events
array of string
required

Event types this endpoint is subscribed to; only matching events are delivered. Change the set with Update a webhook endpoint.

status
string
required

Delivery state of the endpoint.

  • active: The initial state; events are being delivered normally.
  • degraded: Recent deliveries are failing. We keep delivering and retrying, and the endpoint returns to active automatically once deliveries succeed again.
  • paused: All delivery is stopped, either because an update set status to paused or automatically after sustained delivery failures. A paused endpoint never resumes on its own: re-enable it with Update a webhook endpoint, then Replay failed deliveries to recover the deliveries that failed before the pause. Events that arrived while it was paused were never attempted, so a replay does not reach them.

Possible values: active, degraded, paused

destination
object

How each delivery to the endpoint is built.

Show child attributes

Posts the signed event to the endpoint's url unchanged.

destination.type
string
required

Value: webhook

created_at
string
required
updated_at
string
required