neosourceDocs
Search docs

Create a webhook

POST/api/repos/{owner}/{repo}/hooks

createWebhook

Registers a new webhook on a repository. Requires admin access.

Requires authentication using a bearer token or a session cookie — see tokens and scopes.

curl

curl -X POST 'https://neosource.dev/api/repos/OWNER/REPO/hooks' \
  -H 'Authorization: Bearer $NEOSOURCE_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{"url":"string","events":[]}'

fetch

fetch("https://neosource.dev/api/repos/OWNER/REPO/hooks", {
  method: "POST",
  headers: {
    Authorization: "Bearer $NEOSOURCE_TOKEN",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({"url":"string","events":[]}),
});

Path parameters

ownerrequired

Repository owner or organization slug.

string

reporequired

Repository name.

string

Request bodyrequired

application/json

CreateWebhookRequest

object

active

boolean

Whether the webhook is active. Defaults to true.

eventsrequired

array

Event types to subscribe to. The vocabulary is closed by design — `push` and `pull_request` are the only events emitted today.

items

WebhookEventType

string

User-facing event types for webhook subscriptions. The vocabulary is deliberately closed today (`push` / `pull_request` are the only events we emit); the `OpenAPI` spec advertises it as a real enum so SDK clients get exhaustive types. New events extend this enum.

"push""pull_request""mention""assigned""review_requested""issue_comment"

secret

string | null

HMAC secret for signing payloads.

urlrequired

string

Target URL for webhook delivery.

Responses

201Webhook created

application/json

WebhookResponse

object

activerequired

boolean

created_atrequired

integerint64

eventsrequired

array

Event types this webhook is subscribed to.

items

WebhookEventType

string

User-facing event types for webhook subscriptions. The vocabulary is deliberately closed today (`push` / `pull_request` are the only events we emit); the `OpenAPI` spec advertises it as a real enum so SDK clients get exhaustive types. New events extend this enum.

"push""pull_request""mention""assigned""review_requested""issue_comment"

repo_idrequired

string

updated_atrequired

integerint64

urlrequired

string

webhook_idrequired

string

Standard errors

Bodies documented once for the whole API — see standard errors.

  • 400Bad Request — one of: invalid_input
  • 401Authentication required
  • 403Forbidden — one of: forbidden
  • 404Not Found — one of: not_found
  • 409Conflict — one of: already_exists, conflict, non_fast_forward
  • 423Locked — one of: busy
  • 429Rate limited — retry after the `Retry-After` header
  • 500Internal server error
  • 503Service temporarily unavailable / at capacity — retry after the `Retry-After` header
  • 504Gateway timeout — the request exceeded the server's handling budget