# Update a webhook endpoint

> Changes the url, description or event types, or turns the endpoint off and on (`enabled`).

`PATCH /v1/webhook-endpoints/{endpointId}`

Changes the url, description or event types, or turns the endpoint off and on (`enabled`). Turning it on clears a 'failing' switch-off; it is refused (409 `key_invalid`) while the key is revoked or expired.

**Permissions:** any valid key · **Kind:** write · **Cost:** 2 units

Cannot be undone.

## Path parameters

| Field | Type | Required | Description |
|---|---|---|---|
| `endpointId` | uuid | yes |  |

## Body

| Field | Type | Required | Description |
|---|---|---|---|
| `url` | string |  | max 2048 chars |
| `description` | string |  | max 200 chars |
| `eventTypes` | "trip.created" \| "trip.updated" \| "trip.archived" \| "trip.restored" \| "trip.published" \| "trip.unpublished" \| "trip.deleted" \| "trip.itinerary.updated" \| "quote.created" \| "quote.updated" \| "quote.sent" \| "quote.accepted" \| "quote.rejected" \| "quote.deleted" \| "traveler.added" \| "traveler.updated" \| "traveler.removed" \| "trip.contact.updated" \| "document.created" \| "document.updated" \| "document.deleted"[] |  | The event types to receive. Only types this key can READ are accepted (e.g. traveler.* needs travelers:read). max 21 items |
| `enabled` | boolean |  |  |

## Response `200`

| Field | Type | Required | Description |
|---|---|---|---|
| `object` | "webhook_endpoint" | yes |  |
| `id` | uuid | yes |  |
| `url` | string | yes |  |
| `description` | string | yes |  |
| `eventTypes` | "trip.created" \| "trip.updated" \| "trip.archived" \| "trip.restored" \| "trip.published" \| "trip.unpublished" \| "trip.deleted" \| "trip.itinerary.updated" \| "quote.created" \| "quote.updated" \| "quote.sent" \| "quote.accepted" \| "quote.rejected" \| "quote.deleted" \| "traveler.added" \| "traveler.updated" \| "traveler.removed" \| "trip.contact.updated" \| "document.created" \| "document.updated" \| "document.deleted"[] | yes |  |
| `enabled` | boolean | yes |  |
| `disabledReason` | "manual" \| "failing" \| "key_invalid" \| null | yes | Why it is off: switched off by a person, failing for 3 days, or its key is no longer usable. |
| `keyId` | uuid | yes | The API key it belongs to; its events are read with this key's permissions. |
| `previousSecretExpiresAt` | string \| null | yes | After a rotation, the old secret keeps signing until this moment. |
| `lastSuccessAt` | string \| null | yes |  |
| `failingSince` | string \| null | yes |  |
| `createdAt` | string | yes |  |
| `updatedAt` | string | yes |  |

## Errors

Errors are [problem details](https://api.bymundi.com/docs/guides/errors.md). Besides the refusals described above, any call like this one can return:

- [`invalid_request`](https://api.bymundi.com/problems/invalid_request.md) — Invalid request
- [`unauthorized`](https://api.bymundi.com/problems/unauthorized.md) — Missing or invalid API key
- [`insufficient_scope`](https://api.bymundi.com/problems/insufficient_scope.md) — Missing permission
- [`rate_limited`](https://api.bymundi.com/problems/rate_limited.md) — Rate limit reached
- [`not_found`](https://api.bymundi.com/problems/not_found.md) — Not found
- [`idempotency_key_reused`](https://api.bymundi.com/problems/idempotency_key_reused.md) — Idempotency-Key reused
- [`request_in_progress`](https://api.bymundi.com/problems/request_in_progress.md) — Request in progress

## Examples

#### curl

```bash
curl -X PATCH https://api.bymundi.com/v1/webhook-endpoints/$ENDPOINT_ID \
  -H "Authorization: Bearer $BYMUNDI_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{}'
```

#### JavaScript

```javascript
const res = await fetch(`https://api.bymundi.com/v1/webhook-endpoints/${endpointId}`, {
  method: "PATCH",
  headers: {
    Authorization: `Bearer ${process.env.BYMUNDI_KEY}`,
    "Content-Type": "application/json",
    "Idempotency-Key": crypto.randomUUID(),
  },
  body: JSON.stringify({}),
});
if (!res.ok) throw new Error((await res.json()).detail);
const data = await res.json();
```

#### Python

```python
import os, uuid, requests

res = requests.patch(
    f"https://api.bymundi.com/v1/webhook-endpoints/{endpointId}",
    headers={"Authorization": f"Bearer {os.environ['BYMUNDI_KEY']}", "Idempotency-Key": str(uuid.uuid4())},
    json={},
)
res.raise_for_status()
data = res.json()
```
