> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trailercast.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Register a webhook endpoint



## OpenAPI

````yaml api-reference/openapi.yaml POST /webhooks
openapi: 3.1.0
info:
  title: TrailerCast Integration API
  version: 1.0.0
  summary: >-
    Read-only access to call summaries, prospect engagement and Decision Room
    metrics, plus signed webhooks.
  description: >
    Read-only, workspace-scoped API for pulling the deal signals TrailerCast
    captures during a sale,

    and outbound webhooks for near-real-time notification. Start with the guides
    in this section (Introduction, Quickstart, Authentication, Webhooks); the
    endpoint pages below are generated from this spec.


    **Authentication.** Data endpoints take an API key: `Authorization: Bearer
    tck_live_…`.

    Management endpoints take an admin session JWT with the `integrations.crm`
    permission.


    **Pagination.** Every list is keyset-paginated and ascending: `{ data,
    nextCursor, hasMore }`.

    Pass `cursor=<nextCursor>` to continue. `limit` 1–500, default 100.


    **Rate limit.** 300 requests/minute per API key; `429` with `Retry-After`
    when exceeded.


    **Versioning.** Breaking changes ship as a new path (`/api/v2`). Additive
    changes (new fields,

    event types, parameters) may ship at any time; ignore what you do not
    recognise.
  contact:
    name: TrailerCast
    url: https://trailercast.io
servers:
  - url: https://{host}/api/v1
    variables:
      host:
        default: trailercst-backend-production.up.railway.app
        description: Your TrailerCast API host.
  - url: http://localhost:5000/api/v1
    description: Local development
security:
  - apiKey: []
tags:
  - name: Status
  - name: Calls
  - name: Engagement
  - name: Decision Rooms
  - name: Webhook deliveries
  - name: Management — API keys
  - name: Management — Webhooks
paths:
  /webhooks:
    post:
      tags:
        - Management — Webhooks
      summary: Register a webhook endpoint (secret returned once)
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - url
              properties:
                url:
                  type: string
                  format: uri
                  description: https
                  public host: null
                  no embedded credentials.: null
                events:
                  type: array
                  items:
                    type: string
                  default:
                    - '*'
                  description: Event types to receive, or ["*"].
                description:
                  type: string
                  maxLength: 200
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                type: object
                properties:
                  secret:
                    type: string
                    description: Signing secret. Shown once.
                    example: whsec_…
                  data:
                    $ref: '#/components/schemas/WebhookEndpoint'
        '400':
          $ref: '#/components/responses/BadRequest'
      security:
        - sessionJwt: []
components:
  schemas:
    WebhookEndpoint:
      type: object
      properties:
        id:
          type: integer
        url:
          type: string
          format: uri
        description:
          type:
            - string
            - 'null'
        events:
          type: array
          items:
            type: string
        enabled:
          type: boolean
        disabledReason:
          type:
            - string
            - 'null'
        createdAt:
          type: string
          format: date-time
        lastSuccessAt:
          type:
            - string
            - 'null'
          format: date-time
        lastError:
          type:
            - string
            - 'null'
        lastErrorAt:
          type:
            - string
            - 'null'
          format: date-time
        consecutiveFailures:
          type: integer
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: string
          description: Human-readable; not stable.
        code:
          type: string
          description: Stable machine code.
  responses:
    BadRequest:
      description: Invalid input
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: cursor is not a valid cursor for this endpoint.
            code: INVALID_CURSOR
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      bearerFormat: tck_live_…
      description: Workspace API key minted via POST /api-keys. Read-only.
    sessionJwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Admin session token (integrations.crm permission). Management endpoints
        only.

````