Ghost Admin - Webhooks API

Outbound webhook management.

OpenAPI Specification

ghost-org-admin-webhooks-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Ghost Content and Admin APIs Admin - Images Admin - Webhooks API
  description: 'Ghost is an open-source (MIT) publishing platform for professional publications, newsletters, memberships, and paid subscriptions. Every Ghost site - whether self-hosted or on managed Ghost(Pro) - exposes two documented public REST APIs under https://{admin_domain}/ghost/api/.


    The Content API is read-only and is authenticated with a Content API key passed as the `key` query parameter; it serves published posts, pages, authors, tags, tiers, and public settings for consumption by front-ends and static sites.


    The Admin API is read-write and is authenticated with an Admin API key that is used to sign a short-lived JWT sent as `Authorization: Ghost {token}` (a staff access token or user session may also be used). It manages posts, pages, members, tags, labels, tiers, offers, newsletters, users, images, themes, and webhooks.


    The `{admin_domain}` server variable is the site''s domain (for Ghost(Pro), typically a `*.ghost.io` domain). All requests must use HTTPS. The `Accept-Version` header (for example `v5.0`) declares the minimum compatible API version.'
  version: '5.0'
  contact:
    name: Ghost
    url: https://ghost.org
  license:
    name: MIT
    url: https://github.com/TryGhost/Ghost/blob/main/LICENSE
servers:
- url: https://{admin_domain}/ghost/api
  description: A Ghost site's API root (self-hosted or Ghost(Pro))
  variables:
    admin_domain:
      default: demo.ghost.io
      description: The domain of the Ghost site (Ghost(Pro) uses *.ghost.io).
security:
- contentApiKey: []
- adminJwt: []
tags:
- name: Admin - Webhooks
  description: Outbound webhook management.
paths:
  /admin/webhooks/:
    post:
      operationId: addAdminWebhook
      tags:
      - Admin - Webhooks
      summary: Create a webhook
      description: Registers an outbound webhook that fires on a Ghost event (for example post.published, member.added). There is no endpoint to read existing webhooks.
      parameters:
      - $ref: '#/components/parameters/AcceptVersion'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WebhooksRequest'
      responses:
        '201':
          description: The created webhook.
  /admin/webhooks/{id}/:
    put:
      operationId: editAdminWebhook
      tags:
      - Admin - Webhooks
      summary: Update a webhook
      parameters:
      - $ref: '#/components/parameters/AcceptVersion'
      - $ref: '#/components/parameters/PathId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WebhooksRequest'
      responses:
        '200':
          description: The updated webhook.
    delete:
      operationId: deleteAdminWebhook
      tags:
      - Admin - Webhooks
      summary: Delete a webhook
      parameters:
      - $ref: '#/components/parameters/AcceptVersion'
      - $ref: '#/components/parameters/PathId'
      responses:
        '204':
          description: The webhook was deleted.
components:
  parameters:
    AcceptVersion:
      name: Accept-Version
      in: header
      required: false
      description: Minimum compatible API version, for example v5.0.
      schema:
        type: string
        example: v5.0
    PathId:
      name: id
      in: path
      required: true
      description: The resource ID.
      schema:
        type: string
  schemas:
    WebhooksRequest:
      type: object
      properties:
        webhooks:
          type: array
          items:
            type: object
            properties:
              event:
                type: string
                example: post.published
              target_url:
                type: string
                format: uri
              name:
                type: string
              secret:
                type: string
  securitySchemes:
    contentApiKey:
      type: apiKey
      in: query
      name: key
      description: Content API key from a Custom Integration, passed as the `key` query parameter. Safe for browser use; grants read-only access to public data.
    adminJwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'Admin API access. An Admin API key (id:secret) is used to sign a short-lived JWT sent as `Authorization: Ghost {token}`. A staff access token or an authenticated user session may also be used.'