API reference / Webhooks
Webhooks
Webhook endpoints receive signed HTTP POST deliveries when jobs succeed or fail. Each delivery carries a Tend-Signature header containing an HMAC-SHA256 signature of the raw request body, computed with the endpoint's signing secret, so you can verify it came from Tend. Your endpoint must respond with a 2xx within 15 seconds; failed deliveries are retried with backoff for 48 hours.
The webhook object
| Field | Type | Description |
|---|---|---|
id | string | Unique webhook endpoint identifier, prefixed whk_. Immutable. |
url | string | HTTPS URL that receives deliveries. |
events | array of string | Subscribed event types, such as job.succeeded and job.failed. |
secret | string | Signing secret beginning with whsec_. Returned in full only when the endpoint is created. |
status | string | Either enabled or disabled. Endpoints that fail continuously for the full 48-hour window are disabled automatically. |
description | string | Optional free-text label for your own reference. |
created_at | string (ISO 8601) | Timestamp of endpoint creation, in UTC. |
#Create a webhook endpoint
POST /v2/webhooks
Registers an HTTPS endpoint to receive signed event deliveries. The response includes the signing secret exactly once, so store it before discarding the response. Deliveries are verified by computing an HMAC-SHA256 of the raw body with this secret and comparing it to the Tend-Signature header.
| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
url | body | string | yes | HTTPS URL that will receive deliveries. |
events | body | array of string | yes | Event types to subscribe to, for example ["job.succeeded","job.failed"]. |
description | body | string | no | Optional label, up to 200 characters. |
curl -X POST https://api.tendcomputer.com/v2/webhooks \
-H "Authorization: Bearer tnd_live_8fQ2xLm9Zc41" \
-H "Content-Type: application/json" \
-d '{"url":"https://api.example-shop.dev/tend/events","events":["job.succeeded","job.failed"],"description":"Production result handler"}'{
"id": "whk_01J0B3H7E6",
"url": "https://api.example-shop.dev/tend/events",
"events": ["job.succeeded", "job.failed"],
"secret": "whsec_4nTq8VbK2xJd7RmY",
"status": "enabled",
"description": "Production result handler",
"created_at": "2026-05-13T15:02:33Z"
}#List webhook endpoints
GET /v2/webhooks
Returns every webhook endpoint in the current environment with cursor-based pagination. Signing secrets are masked in list responses and show only their final four characters. Use limit (default 50, maximum 200) and next_cursor to page.
| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
limit | query | integer | no | Page size. Default 50, maximum 200. |
cursor | query | string | no | The next_cursor value from the previous response. |
status | query | string | no | Filter by enabled or disabled. |
curl https://api.tendcomputer.com/v2/webhooks \
-H "Authorization: Bearer tnd_live_8fQ2xLm9Zc41"{
"data": [
{
"id": "whk_01J0B3H7E6",
"url": "https://api.example-shop.dev/tend/events",
"events": ["job.succeeded", "job.failed"],
"secret": "whsec_••••••••mRY",
"status": "enabled",
"description": "Production result handler",
"created_at": "2026-05-13T15:02:33Z"
}
],
"next_cursor": null
}#Update a webhook endpoint
PATCH /v2/webhooks/{webhook_id}
Changes the URL, event subscriptions, description, or status of an endpoint. Setting status to enabled re-enables an endpoint that was disabled after exhausting its 48-hour retry window; deliveries dropped during that period are not replayed. The signing secret does not change.
| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
webhook_id | path | string | yes | The webhook ID, beginning with whk_. |
url | body | string | no | New HTTPS delivery URL. |
events | body | array of string | no | Replacement list of subscribed event types. |
status | body | string | no | Set to enabled or disabled. |
curl -X PATCH https://api.tendcomputer.com/v2/webhooks/whk_01J0B3H7E6 \
-H "Authorization: Bearer tnd_live_8fQ2xLm9Zc41" \
-H "Content-Type: application/json" \
-d '{"events":["job.failed"]}'{
"id": "whk_01J0B3H7E6",
"url": "https://api.example-shop.dev/tend/events",
"events": ["job.failed"],
"secret": "whsec_••••••••mRY",
"status": "enabled",
"description": "Production result handler",
"created_at": "2026-05-13T15:02:33Z"
}#Delete a webhook endpoint
DELETE /v2/webhooks/{webhook_id}
Permanently removes an endpoint and stops all future deliveries to it. Deliveries already queued for retry are discarded. To pause deliveries temporarily, set status to disabled with the update endpoint instead.
| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
webhook_id | path | string | yes | The webhook ID, beginning with whk_. |
curl -X DELETE https://api.tendcomputer.com/v2/webhooks/whk_01J0B3H7E6 \
-H "Authorization: Bearer tnd_live_8fQ2xLm9Zc41"{
"id": "whk_01J0B3H7E6",
"deleted": true
}