Drippay Webhooks API

Manage webhook endpoints for real-time event notifications.

OpenAPI Specification

drippay-webhooks-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Drip BillableMetrics Webhooks API
  description: "\n# Drip API\n\n**Usage-based billing + execution ledger.**\n\n---\n\n## 60-Second Quickstart (Core SDK)\n\n### 1. Install\n\n```bash\nnpm install @drip-sdk/node\n```\n\n### 2. Set your API key\n\n```bash\n# Secret key - full API access (server-side only, never expose publicly)\nexport DRIP_API_KEY=sk_test_...\n\n# Use a secret key for the customer, billing, runs, pricing-plan, and webhook\n# flows documented in this reference.\n```\n\nOr use a \".env\" file (recommended):\n\n```bash\nnpm install dotenv\n# .env\nDRIP_API_KEY=sk_test_...\n```\n\nLoad your \".env\" at the top of your entry file:\n\n```typescript\nimport 'dotenv/config';\n```\n\n### 3. Create a customer and track usage\n\n```typescript\nimport 'dotenv/config';\nimport { drip } from '@drip-sdk/node';\n\n// Create a customer first\nconst customer = await drip.createCustomer({ externalCustomerId: 'user_123' });\n\n// Internal tracking only (no billing)\nawait drip.trackUsage({ customerId: customer.id, meter: 'api_calls', quantity: 1 });\n```\n\nThe `drip` singleton reads `DRIP_API_KEY` from your environment automatically.\n\n### Alternative: Explicit Configuration\n\n```typescript\nimport 'dotenv/config';\nimport { Drip } from '@drip-sdk/node';\n\n// Auto-reads DRIP_API_KEY from environment\nconst client = new Drip();\n\n// Or pass config explicitly with an Admin/Operator secret key\nconst clientWithSecret = new Drip({ apiKey: 'sk_test_...' });\n```\n\n### Full Example (Node.js)\n\n```typescript\nimport 'dotenv/config';\nimport { drip } from '@drip-sdk/node';\n\nasync function main() {\n  // Verify connectivity\n  await drip.ping();\n\n  // Create a customer (at least one of externalCustomerId or onchainAddress required)\n  const customer = await drip.createCustomer({ externalCustomerId: 'user_123' });\n\n  // Internal tracking (no billing)\n  await drip.trackUsage({\n    customerId: customer.id,\n    meter: 'llm_tokens',\n    quantity: 842,\n    metadata: { model: 'gpt-4o-mini' },\n  });\n\n  // Billable usage\n  await drip.charge({\n    customerId: customer.id,\n    meter: 'api_calls',\n    quantity: 1,\n  });\n\n  // Record an execution lifecycle\n  await drip.recordRun({\n    customerId: customer.id,\n    workflow: 'research-agent',\n    events: [\n      { eventType: 'llm.call', quantity: 1700, units: 'tokens' },\n      { eventType: 'tool.call', quantity: 1 },\n    ],\n    status: 'COMPLETED',\n  });\n\n  console.log(`Customer ${customer.id}: usage + run recorded`);\n}\n\nmain();\n```\n\n```python\nfrom drip import drip\n\n# Create a customer first\ncustomer = drip.create_customer(external_customer_id=\"user_123\")\n\n# Internal tracking only (no billing)\ndrip.track_usage(customer_id=customer.id, meter=\"api_calls\", quantity=1)\n```\n\nThe `drip` singleton reads `DRIP_API_KEY` from your environment automatically.\n\n### Alternative: Explicit Configuration (Python)\n\n```python\nfrom drip import Drip\n\n# Auto-reads DRIP_API_KEY from environment\nclient = Drip()\n\n# Or pass config explicitly with an Admin/Operator secret key\nclient_with_secret = Drip(api_key=\"sk_test_...\")\n```\n\n### Full Example (Python)\n\n```python\nfrom drip import drip\n\n# Verify connectivity\ndrip.ping()\n\n# Create a customer (at least one of external_customer_id or onchain_address required)\ncustomer = drip.create_customer(external_customer_id=\"user_123\")\n\n# Internal tracking (no billing)\ndrip.track_usage(\n    customer_id=customer.id,\n    meter=\"llm_tokens\",\n    quantity=842,\n    metadata={\"model\": \"gpt-4o-mini\"}\n)\n\n# Billable usage\ndrip.charge(\n    customer_id=customer.id,\n    meter=\"api_calls\",\n    quantity=1\n)\n\n# Record execution lifecycle\ndrip.record_run(\n    customer_id=customer.id,\n    workflow=\"research-agent\",\n    events=[\n        {\"event_type\": \"llm.call\", \"quantity\": 1700, \"units\": \"tokens\"},\n        {\"event_type\": \"tool.call\", \"quantity\": 1},\n    ],\n    status=\"COMPLETED\"\n)\n\nprint(f\"Customer {customer.id}: usage + run recorded\")\n```\n\n**Expected result:**\n- No errors\n- Events appear in your Drip dashboard within seconds\n\n**Install:** `npm install @drip-sdk/node` or `pip install drip-sdk`\n\n**Set API key:** `export DRIP_API_KEY=sk_test_...` or use a \".env\" file with `DRIP_API_KEY=sk_test_...` and load it with `import 'dotenv/config'` (for Node.js)\n\n---\n\n## REST API Quick Start\n\n### Step 1: Create a customer\n\n```bash\ncurl -X POST https://api.drippay.dev/v1/customers \\\n  -H \"Authorization: Bearer sk_test_YOUR_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"externalCustomerId\": \"user_123\"}'\n```\n\n**You'll get back:**\n```json\n{\n  \"id\": \"cmlxxxxxx...\",\n  \"externalCustomerId\": \"user_123\",\n  \"status\": \"ACTIVE\"\n}\n```\n\n### Step 2: Create pricing\n\nUse the same meter string in your pricing plan and your usage calls:\n\n```bash\ncurl -X POST https://api.drippay.dev/v1/pricing-plans \\\n  -H \"Authorization: Bearer sk_test_YOUR_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"name\": \"API Calls\",\n    \"unitType\": \"api_calls\",\n    \"unitPriceUsd\": 0.001\n  }'\n```\n\n### Step 3: Charge usage\n\n```bash\ncurl -X POST https://api.drippay.dev/v1/usage \\\n  -H \"Authorization: Bearer sk_test_YOUR_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"customerId\": \"CUSTOMER_ID_FROM_STEP_1\",\n    \"usageType\": \"api_calls\",\n    \"quantity\": 100,\n    \"idempotencyKey\": \"charge_001\"\n  }'\n```\n\n---\n\n## SDK Methods\n\n### Node.js (`@drip-sdk/node`)\n\n| Method | Description |\n|--------|-------------|\n| `createCustomer()` | Create a customer |\n| `getCustomer()` | Get customer details |\n| `listCustomers()` | List all customers |\n| `trackUsage()` | Record internal usage without billing |\n| `charge()` | Record usage and charge (requires pricing plan) |\n| `emitEvent()` | Record an execution event |\n| `recordRun()` | Record a complete agent run |\n| `startRun()` | Start a run |\n| `endRun()` | End a run |\n| `getBalance()` | Get customer balance |\n\n### Python (`drip-sdk`)\n\n| Method | Description |\n|--------|-------------|\n| `create_customer()` | Create a customer |\n| `get_customer()` | Get customer details |\n| `list_customers()` | List all customers |\n| `track_usage()` | Record internal usage without billing |\n| `charge()` | Record usage and charge (requires pricing plan) |\n| `emit_event()` | Record an execution event |\n| `record_run()` | Record a complete agent run |\n| `start_run()` | Start a run |\n| `end_run()` | End a run |\n| `get_balance()` | Get customer balance |\n\n---\n\n## Two Modes\n\n| Mode | How | When |\n|------|-----|------|\n| **Tracking only** | `trackUsage()` / `track_usage()` | Pilots, analytics, no billing yet |\n| **Billing** | `charge()` + pricing plan | Ready to charge customers |\n\nBoth modes record usage in the ledger. The difference is whether a charge is created.\n\nUse `POST /v1/usage/internal` when you want tracking only.\n\n---\n\n## Authentication\n\n```\nAuthorization: Bearer sk_test_YOUR_KEY\n```\n\n### Key Types\n\n| Key Prefix | Use For |\n|------------|---------|\n| `sk_test_*` / `sk_live_*` | Server-side API access (secret key) |\n| `pk_test_*` / `pk_live_*` | Public key identifier. The role-protected endpoints in this reference require a secret key |\n\n### API Key Roles\n\nSecret keys (`sk_*`) are assigned a role that controls which endpoints they can access. Roles are hierarchical: higher roles include all permissions of lower roles.\n\n| Role | Level | Permissions |\n|------|-------|-------------|\n| `READONLY` | Lowest | List and read resources (customers, charges, pricing plans, events) |\n| `OPERATOR` | Mid | + Create customers, charge usage, track internal usage, emit events, manage runs |\n| `ADMIN` | Highest | + Create/update/delete pricing plans, manage contracts, manage API keys |\n\nPublic keys (`pk_*`) are always `READONLY`: they cannot create or modify resources.\n\n> **Important:** To create, update, or delete **pricing plans** and **contracts**, you must use a secret key (`sk_*`) with the **ADMIN** role. Using a lower-role key returns `403 Forbidden`.\n\n---\n\n## Idempotency\n\nAlways include `idempotencyKey` in POST requests to prevent duplicates:\n\n```json\n{\n  \"customerId\": \"cmlxxxxxx...\",\n  \"usageType\": \"api_calls\",\n  \"quantity\": 1,\n  \"idempotencyKey\": \"req_unique_12345\"\n}\n```\n\nSame key = same result. Safe to retry on network failures.\n\n---\n\n## Error Codes\n\n| Status | Meaning | Fix |\n|--------|---------|-----|\n| **400** | Bad request | Check request body matches schema |\n| **401** | Invalid API key | Verify `Authorization: Bearer sk_...` header |\n| **404** | Not found | Customer/pricing plan doesn't exist. Create customer first. |\n| **409** | Duplicate | Resource with this ID already exists |\n| **422** | Validation error | Check required fields and types |\n\n---\n\n## Important Notes\n\n- **Always create a customer first** for billable onboarding flows. You cannot use made-up customer IDs.\n- **`POST /v1/events`** records execution events (what happened). It does **not** auto-create charges.\n- **`POST /v1/usage`** records usage and creates charges if a matching pricing plan exists.\n- **`POST /v1/usage/internal`** records usage without billing.\n- **Numbers as strings**: Monetary amounts are returned as strings (e.g., `\"0.001000\"`) to preserve precision.\n"
  version: 1.0.0
  contact:
    name: Drip Support
    email: support@drippay.dev
  x-logo:
    url: https://drippay.dev/logo.svg
    altText: Drip
servers:
- url: https://api.drippay.dev
  description: Production
- url: http://localhost:3001
  description: Development
security:
- bearerAuth: []
tags:
- name: Webhooks
  description: Manage webhook endpoints for real-time event notifications.
paths:
  /v1/webhooks/events:
    get:
      operationId: listWebhookEventTypes
      summary: List webhook event types
      tags:
      - Webhooks
      description: Get all available webhook event types with descriptions. **Requires a secret key (sk_).** Public keys (pk_) will receive a 403 error.
      responses:
        '200':
          description: Available event types
          content:
            application/json:
              schema:
                description: Available event types
                type: object
                properties:
                  events:
                    type: array
                    items:
                      type: string
                    description: List of all available event types
                    example:
                    - charge.succeeded
                    - charge.failed
                    - customer.balance.low
                    - customer.deposit.confirmed
                  description:
                    type: object
                    additionalProperties:
                      type: string
                    description: Human-readable descriptions for each event type
                    example:
                      charge.succeeded: Charge confirmed on-chain - unlock service, update billing UI
                      charge.failed: Charge failed - trigger retries, alerts, user notification
                      customer.balance.low: Customer drops below configured threshold - prevent surprise outages
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                description: Unauthorized
                type: object
                properties:
                  error:
                    type: string
                    description: Error message
                  code:
                    type: string
                    description: Error code
                  details:
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                        message:
                          type: string
                    description: Validation error details
                required:
                - error
                - code
  /v1/webhooks:
    post:
      operationId: createWebhook
      summary: Create a webhook
      tags:
      - Webhooks
      description: "\nCreate a new webhook endpoint to receive real-time event notifications. **Requires a secret key (sk_).**\n\n**Important:** The `secret` is only returned once on creation. Save it\nimmediately for HMAC signature verification. Public keys (pk_) cannot access this endpoint.\n\n**Signature verification:**\n```javascript\nconst signature = crypto\n  .createHmac('sha256', secret)\n  .update(JSON.stringify(payload))\n  .digest('hex');\n// Compare with X-Drip-Signature header\n```\n        "
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              description: Request body for creating a webhook endpoint.
              properties:
                url:
                  type: string
                  format: uri
                  description: HTTPS endpoint URL. Must be publicly accessible and return 200 OK within 30 seconds.
                  example: https://api.example.com/webhooks/drip
                events:
                  type: array
                  description: Event types to subscribe to. Use ["*"] for all events.
                  items:
                    type: string
                  example:
                  - charge.succeeded
                  - charge.failed
                  - customer.balance.low
                description:
                  type: string
                  description: Optional description to help identify this webhook
                  example: Production billing notifications
              required:
              - url
              - events
        description: Request body for creating a webhook endpoint.
      responses:
        '201':
          description: Webhook created
          content:
            application/json:
              schema:
                description: Webhook created
                type: object
                properties:
                  id:
                    type: string
                    description: Unique webhook identifier
                    example: whk_abc123def456
                  url:
                    type: string
                    format: uri
                    description: Your webhook endpoint
                    example: https://api.example.com/webhooks/drip
                  events:
                    type: array
                    items:
                      type: string
                    description: Subscribed event types
                    example:
                    - charge.succeeded
                    - charge.failed
                    - customer.balance.low
                  description:
                    type: string
                    nullable: true
                    description: Optional description
                    example: Production billing events
                  isActive:
                    type: boolean
                    description: Whether the webhook is active
                    example: true
                  secret:
                    type: string
                    description: HMAC secret for signature verification. SAVE THIS - it will not be shown again!
                    example: whsec_abcdef123456789...
                  createdAt:
                    type: string
                    format: date-time
                    example: '2024-01-15T10:30:00.000Z'
                  updatedAt:
                    type: string
                    format: date-time
                    example: '2024-01-15T10:30:00.000Z'
                  message:
                    type: string
                    description: Reminder to save the secret
                    example: Save the secret - it will not be shown again!
        '400':
          description: Invalid URL or events
          content:
            application/json:
              schema:
                description: Invalid URL or events
                type: object
                properties:
                  error:
                    type: string
                    description: Error message
                  code:
                    type: string
                    description: Error code
                  details:
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                        message:
                          type: string
                    description: Validation error details
                required:
                - error
                - code
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                description: Unauthorized
                type: object
                properties:
                  error:
                    type: string
                    description: Error message
                  code:
                    type: string
                    description: Error code
                  details:
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                        message:
                          type: string
                    description: Validation error details
                required:
                - error
                - code
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                description: Forbidden
                type: object
                properties:
                  error:
                    type: string
                    description: Error message
                  code:
                    type: string
                    description: Error code
                  details:
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                        message:
                          type: string
                    description: Validation error details
                required:
                - error
                - code
    get:
      operationId: listWebhooks
      summary: List webhooks
      tags:
      - Webhooks
      description: Get all webhooks for your business with delivery statistics. **Requires a secret key (sk_).** Public keys (pk_) will receive a 403 error.
      responses:
        '200':
          description: List of webhooks
          content:
            application/json:
              schema:
                description: List of webhooks
                type: object
                properties:
                  data:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                          description: Unique webhook identifier
                          example: whk_abc123def456
                        url:
                          type: string
                          format: uri
                          description: Endpoint URL that receives events
                          example: https://api.example.com/webhooks/drip
                        events:
                          type: array
                          items:
                            type: string
                          description: Event types this webhook subscribes to
                          example:
                          - charge.succeeded
                          - charge.failed
                        description:
                          type: string
                          nullable: true
                          description: Optional description
                          example: Production billing events
                        isActive:
                          type: boolean
                          description: Whether the webhook is active
                          example: true
                        healthStatus:
                          type: string
                          enum:
                          - HEALTHY
                          - DEGRADED
                          - UNHEALTHY
                          description: Health status from circuit breaker
                          example: HEALTHY
                        consecutiveFailures:
                          type: integer
                          description: Number of consecutive delivery failures
                          example: 0
                        lastHealthChange:
                          type: string
                          format: date-time
                          nullable: true
                          description: When health status last changed
                          example: null
                        createdAt:
                          type: string
                          format: date-time
                          example: '2024-01-15T10:30:00.000Z'
                        updatedAt:
                          type: string
                          format: date-time
                          example: '2024-01-15T10:30:00.000Z'
                        stats:
                          type: object
                          description: Delivery statistics for this webhook
                          properties:
                            total:
                              type: integer
                              description: Total events sent
                              example: 1250
                            delivered:
                              type: integer
                              description: Successfully delivered
                              example: 1245
                            failed:
                              type: integer
                              description: Failed after retries
                              example: 3
                            pending:
                              type: integer
                              description: Currently retrying
                              example: 2
                  count:
                    type: integer
                    description: Total webhooks
                    example: 2
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                description: Unauthorized
                type: object
                properties:
                  error:
                    type: string
                    description: Error message
                  code:
                    type: string
                    description: Error code
                  details:
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                        message:
                          type: string
                    description: Validation error details
                required:
                - error
                - code
  /v1/webhooks/{id}:
    get:
      operationId: getWebhook
      summary: Get a webhook
      tags:
      - Webhooks
      description: Retrieve a webhook by ID with delivery statistics. **Requires a secret key (sk_).**
      parameters:
      - schema:
          type: string
        in: path
        name: id
        required: true
        description: Webhook ID
      responses:
        '200':
          description: Webhook details
          content:
            application/json:
              schema:
                type: object
                description: Webhook details
                properties:
                  id:
                    type: string
                    description: Unique identifier for the webhook
                    example: whk_abc123def456
                  url:
                    type: string
                    format: uri
                    description: The HTTPS endpoint that receives webhook payloads
                    example: https://api.example.com/webhooks/drip
                  events:
                    type: array
                    description: List of event types this webhook subscribes to
                    items:
                      type: string
                      enum:
                      - charge.succeeded
                      - charge.failed
                      - charge.refunded
                      - usage.recorded
                      - customer.created
                      - customer.deposit.confirmed
                      - customer.withdraw.confirmed
                      - customer.balance.low
                      - customer.usage_cap.reached
                      - customer.spending.warning
                      - customer.spending.blocked
                      - customer.spending.exceeded
                      - webhook.endpoint.unhealthy
                      - api_key.created
                      - api_key.rotated
                      - pricing_plan.updated
                      - transaction.created
                      - transaction.pending
                      - transaction.confirmed
                      - transaction.failed
                      - contract.created
                      - contract.updated
                      - contract.cancelled
                      - subscription.created
                      - subscription.cancelled
                      - invoice.created
                      - invoice.issued
                      - invoice.paid
                      - invoice.voided
                      - entitlement_plan.created
                      - entitlement_plan.updated
                      - entitlement_plan.deleted
                      - customer.entitlement.assigned
                    example:
                    - charge.succeeded
                    - charge.failed
                    - customer.balance.low
                  isActive:
                    type: boolean
                    description: Whether the webhook is currently receiving events
                    example: true
                  secret:
                    type: string
                    description: Secret key for verifying webhook signatures (only returned on creation)
                    example: whsec_abc123...
                  description:
                    type: string
                    description: Optional description for this webhook
                    example: Production billing events
                  createdAt:
                    type: string
                    format: date-time
                    description: When the webhook was created
                    example: '2024-01-15T10:30:00.000Z'
                required:
                - id
                - url
                - events
                - isActive
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: Error message
                  code:
                    type: string
                    description: Error code
                  details:
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                        message:
                          type: string
                    description: Validation error details
                required:
                - error
                - code
                description: Unauthorized
        '404':
          description: Webhook not found
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: Error message
                  code:
                    type: string
                    description: Error code
                  details:
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                        message:
                          type: string
                    description: Validation error details
                required:
                - error
                - code
                description: Webhook not found
    patch:
      operationId: updateWebhook
      summary: Update a webhook
      tags:
      - Webhooks
      description: Update webhook URL, events, or status. **Requires a secret key (sk_).**
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                url:
                  type: string
                  format: uri
                  description: New webhook URL
                events:
                  type: array
                  items:
                    type: string
                  description: Events to subscribe to
                description:
                  type: string
                isActive:
                  type: boolean
                  description: Enable/disable the webhook
      parameters:
      - schema:
          type: string
        in: path
        name: id
        required: true
        description: Webhook ID
      responses:
        '200':
          description: Webhook updated
          content:
            application/json:
              schema:
                type: object
                description: Webhook updated
                properties:
                  id:
                    type: string
                    description: Unique identifier for the webhook
                    example: whk_abc123def456
                  url:
                    type: string
                    format: uri
                    description: The HTTPS endpoint that receives webhook payloads
                    example: https://api.example.com/webhooks/drip
                  events:
                    type: array
                    description: List of event types this webhook subscribes to
                    items:
                      type: string
                      enum:
                      - charge.succeeded
                      - charge.failed
                      - charge.refunded
                      - usage.recorded
                      - customer.created
                      - customer.deposit.confirmed
                      - customer.withdraw.confirmed
                      - customer.balance.low
                      - customer.usage_cap.reached
                      - customer.spending.warning
                      - customer.spending.blocked
                      - customer.spending.exceeded
                      - webhook.endpoint.unhealthy
                      - api_key.created
                      - api_key.rotated
                      - pricing_plan.updated
                      - transaction.created
                      - transaction.pending
                      - transaction.confirmed
                      - transaction.failed
                      - contract.created
                      - contract.updated
                      - contract.cancelled
                      - subscription.created
                      - subscription.cancelled
                      - invoice.created
                      - invoice.issued
                      - invoice.paid
                      - invoice.voided
                      - entitlement_plan.created
                      - entitlement_plan.updated
                      - entitlement_plan.deleted
                      - customer.entitlement.assigned
                    example:
                    - charge.succeeded
                    - charge.failed
                    - customer.balance.low
                  isActive:
                    type: boolean
                    description: Whether the webhook is currently receiv

# --- truncated at 32 KB (52 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/drippay/refs/heads/main/openapi/drippay-webhooks-api-openapi.yml