> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stablemesh.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Set webhook endpoint

> Creates or updates your single webhook endpoint. On first creation the response includes `secret`, the signing secret. Store it; it is not shown again.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/webhook/set
openapi: 3.1.0
info:
  title: StableMesh Open API
  version: 1.0.0
  description: >-
    Issue and manage StableMesh cards from your own server. Every endpoint is
    `POST` with a JSON body, authenticated with your API key in `X-API-KEY`.
  contact:
    email: contact@stablemesh.io
servers:
  - url: https://api.stablemesh.io
    description: Production
security:
  - ApiKey: []
tags:
  - name: Account
    description: Your USD account.
  - name: Deposits
    description: Fund your USD account with stablecoins.
  - name: Cards
    description: Issue, fund and control cards.
  - name: Webhooks
    description: Configure event delivery.
  - name: Sandbox
    description: Simulate deposits and payments in the sandbox.
paths:
  /v1/webhook/set:
    post:
      tags:
        - Webhooks
      summary: Set webhook endpoint
      description: >-
        Creates or updates your single webhook endpoint. On first creation the
        response includes `secret`, the signing secret. Store it; it is not
        shown again.
      operationId: v1_webhook_set
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                url:
                  type: string
                  description: >-
                    HTTPS URL, up to 512 characters. Private and loopback
                    addresses are refused.
                  example: https://example.com/stablemesh/webhooks
                enabled:
                  type: boolean
                  description: Pause or resume delivery. Defaults to `true` on creation.
              required:
                - url
      responses:
        '200':
          description: Success.
          content:
            application/json:
              schema:
                type: object
                properties:
                  code:
                    type: integer
                    description: '`0` on success.'
                    example: 0
                  message:
                    type: string
                    description: '`ok` on success.'
                    example: ok
                  data:
                    $ref: '#/components/schemas/WebhookConfig'
                required:
                  - code
                  - message
                  - data
        '400':
          description: Refused (bad parameter, business rule). Nothing changed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing, invalid, revoked or expired API key (`11002`).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Request from an IP not on the key's allowlist (`11003`).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Over the per-key rate limit (`11004`).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: >-
            Internal error (`9999`). The outcome may be unknown; check state
            before retrying.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    WebhookConfig:
      type: object
      properties:
        configured:
          type: boolean
          example: true
        url:
          type:
            - string
            - 'null'
          description: ''
          example: https://example.com/stablemesh/webhooks
        enabled:
          type:
            - boolean
            - 'null'
          example: true
        secretPrefix:
          type:
            - string
            - 'null'
          description: First characters of the signing secret, to tell secrets apart.
          example: whsec_Xk3pQ9aB
        secret:
          type: string
          description: >-
            The full signing secret. Returned **only** when it was just
            generated (first `webhook/set`, or `webhook/rotateSecret`). Store it
            now.
          example: whsec_Xk3pQ9aBc7…
      required:
        - configured
        - url
        - enabled
        - secretPrefix
    Error:
      type: object
      properties:
        code:
          type: integer
          description: Non-zero error code. See [Errors](/api-reference/errors).
          example: 4011
        message:
          type: string
          description: Human-readable reason.
          example: >-
            This card can't be topped up through the API. Use the dashboard for
            this card.
        data:
          type: object
          description: >-
            Present only when the error carries something you need, e.g.
            `withdrawalId` on a `9999` from `card/withdraw`.
          additionalProperties: true
      required:
        - code
        - message
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: X-API-KEY
      description: >-
        Create keys in the dashboard under **Settings → API keys**. Production
        keys start with `smk_live_`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.