> ## Documentation Index
> Fetch the complete documentation index at: https://gecko.security/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a webhook endpoint



## OpenAPI

````yaml /api-reference/openapi.json post /webhooks
openapi: 3.1.0
info:
  title: Gecko Security API
  version: 1.0.0
  description: >-
    Programmatic access to scans, vulnerabilities, repositories, schedules,
    webhooks, and scanner image releases. Authenticate with an API key via the
    `X-API-Key` header or `Authorization: Bearer <key>`.
servers:
  - url: https://app.gecko.security/api/v1
security:
  - ApiKeyHeader: []
  - BearerAuth: []
paths:
  /webhooks:
    post:
      summary: Create a webhook endpoint
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateWebhookRequest'
      responses:
        '201':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebhookEndpoint'
        '401':
          description: Authentication error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Authorization error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limited
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    CreateWebhookRequest:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        url:
          type: string
          format: uri
        event_types:
          minItems: 1
          type: array
          items:
            type: string
            enum:
              - scan.started
              - scan.completed
              - scan.failed
              - vulnerability.found
              - vulnerability.status_changed
              - repository.scan_completed
              - schedule.triggered
        description:
          type: string
          maxLength: 255
      required:
        - url
        - event_types
      additionalProperties: false
    WebhookEndpoint:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        object:
          type: string
          const: webhook_endpoint
        id:
          type: string
          format: uuid
          pattern: >-
            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
        url:
          type: string
        description:
          anyOf:
            - type: string
            - type: 'null'
        enabled:
          type: boolean
        event_types:
          type: array
          items:
            type: string
        created_at:
          type: string
        secret:
          type: string
      required:
        - object
        - id
        - url
        - description
        - enabled
        - event_types
        - created_at
      additionalProperties: false
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
            code:
              type: string
            message:
              type: string
            param:
              type: string
            doc_url:
              type: string
            request_id:
              type: string
          required:
            - type
            - code
            - message
            - doc_url
            - request_id
      required:
        - error
  securitySchemes:
    ApiKeyHeader:
      type: apiKey
      in: header
      name: X-API-Key
    BearerAuth:
      type: http
      scheme: bearer

````