Hubflo Webhook API

The webhook API from Hubflo — 4 operation(s) for webhook.

Operations 5

POST /api/v2/webhooks/{webhook_target_id}/activation Activates a webhook #
DELETE /api/v2/webhooks/{webhook_target_id}/activation Deactivates a webhook #
GET /api/v2/webhooks/{webhook_target_id}/webhook_deliveries Retrieves the webhook deliveries #
POST /api/v2/webhooks Creates a webhook #
DELETE /api/v2/webhooks/{id} Deletes a webhook #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/hubflo-webhook-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

hubflo-webhook-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Hubflo Webhook API
  version: v2
  description: The Hubflo API allows you to write and read data from the Hubflo application.
servers:
- url: https://app.hubflo.com
  description: The production API server
- url: https://staging.hubflo.com
  description: The staging API server
- url: http://localhost:3000
  description: The local API server
tags:
- name: Webhook
paths:
  /api/v2/webhooks/{webhook_target_id}/activation:
    parameters:
    - name: webhook_target_id
      in: path
      required: true
      description: Webhook ID
      schema:
        type: string
    post:
      summary: Activates a webhook
      security:
      - bearer_auth: []
      description: Activates a webhook so it resumes receiving events
      tags:
      - Webhook
      responses:
        '201':
          description: Webhook activated
          headers:
            Content-Type:
              schema:
                type: string
              description: application/json; charset=utf-8
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
          content:
            application/json:
              examples:
                example:
                  value:
                    id: 1f886b66-1026-45ae-8eee-4e0a0d51c510
                    event_names:
                    - contact_created
                    url: https://www.sample-1.com
                    active: true
                    created_at: '2026-07-17T13:10:11Z'
        '401':
          description: 'unauthorized: the Authorization header is missing or invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 401
                    title: Unauthorized
                    message: Invalid API token
              schema:
                $ref: '#/components/schemas/error_unauthorized'
        '404':
          description: 'not found: the resource is not found'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 404
                    title: Not Found
                    message: Resource not found
              schema:
                $ref: '#/components/schemas/error_not_found'
        '429':
          description: 'too many requests: the user has reached the rate limit'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 429
                    title: Too Many Requests
                    message: Rate limit reached. Please wait for a couple of minutes.
              schema:
                $ref: '#/components/schemas/error_too_many_requests'
      operationId: postApiV2WebhooksByWebhookTargetIdActivation
      x-operation-id-source: derived
    delete:
      summary: Deactivates a webhook
      security:
      - bearer_auth: []
      description: Deactivates a webhook so it stops receiving events
      tags:
      - Webhook
      responses:
        '200':
          description: Webhook deactivated
          headers:
            Content-Type:
              schema:
                type: string
              description: application/json; charset=utf-8
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
          content:
            application/json:
              examples:
                example:
                  value:
                    id: e7b1996e-c76b-4dd0-b133-c91a74f176ff
                    event_names:
                    - contact_created
                    url: https://www.sample-6.com
                    active: false
                    created_at: '2026-07-17T13:10:11Z'
        '401':
          description: 'unauthorized: the Authorization header is missing or invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 401
                    title: Unauthorized
                    message: Invalid API token
              schema:
                $ref: '#/components/schemas/error_unauthorized'
        '404':
          description: 'not found: the resource is not found'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 404
                    title: Not Found
                    message: Resource not found
              schema:
                $ref: '#/components/schemas/error_not_found'
        '429':
          description: 'too many requests: the user has reached the rate limit'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 429
                    title: Too Many Requests
                    message: Rate limit reached. Please wait for a couple of minutes.
              schema:
                $ref: '#/components/schemas/error_too_many_requests'
      operationId: deleteApiV2WebhooksByWebhookTargetIdActivation
      x-operation-id-source: derived
  /api/v2/webhooks/{webhook_target_id}/webhook_deliveries:
    get:
      summary: Retrieves the webhook deliveries
      security:
      - bearer_auth: []
      description: Returns the deliveries sent to a webhook, most recent first, so their status and errors can be audited. Deliveries are retained for one month.
      tags:
      - Webhook
      parameters:
      - name: page
        in: query
        required: false
        description: Page number
        example: 1
        schema:
          type: number
      - name: per_page
        in: query
        required: false
        description: Number of items per page (max 100)
        example: 10
        schema:
          type: number
      - name: webhook_target_id
        in: path
        required: true
        description: Webhook ID
        schema:
          type: string
      - name: errored
        in: query
        required: false
        description: Only return deliveries that errored (transport failure or HTTP status >= 400)
        schema:
          type: boolean
      responses:
        '200':
          description: Webhook deliveries retrieved
          headers:
            Content-Type:
              schema:
                type: string
              description: application/json; charset=utf-8
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
            X-Page:
              schema:
                type: integer
              description: Current page number
            X-Per-Page:
              schema:
                type: integer
              description: Number of items per page
            X-Total-Pages:
              schema:
                type: integer
              description: Total number of pages
            X-Next-Page:
              schema:
                type:
                - integer
                - 'null'
              description: Next page number
            X-Prev-Page:
              schema:
                type:
                - integer
                - 'null'
              description: Previous page number
            X-Total-Count:
              schema:
                type: integer
              description: Total number of items
          content:
            application/json:
              examples:
                example:
                  value:
                  - id: cf626778-7d73-498b-9c5b-d2664cb70553
                    event_name: contact_created
                    state: pending
                    response_code: null
                    payload:
                      data: sample_payload
                      webhook_delivery_id: cf626778-7d73-498b-9c5b-d2664cb70553
                      webhook_delivery_created_at: '2026-07-17T15:10:11.836+02:00'
                    created_at: '2026-07-17T13:10:11Z'
                  - id: 79fe5a96-079b-4a79-98df-3b1a7f7daadf
                    event_name: contact_created
                    state: pending
                    response_code: null
                    payload:
                      data: sample_payload
                      webhook_delivery_id: 79fe5a96-079b-4a79-98df-3b1a7f7daadf
                      webhook_delivery_created_at: '2026-07-17T15:10:11.835+02:00'
                    created_at: '2026-07-17T13:10:11Z'
        '401':
          description: 'unauthorized: the Authorization header is missing or invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 401
                    title: Unauthorized
                    message: Invalid API token
              schema:
                $ref: '#/components/schemas/error_unauthorized'
        '404':
          description: 'not found: the resource is not found'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 404
                    title: Not Found
                    message: Resource not found
              schema:
                $ref: '#/components/schemas/error_not_found'
        '429':
          description: 'too many requests: the user has reached the rate limit'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 429
                    title: Too Many Requests
                    message: Rate limit reached. Please wait for a couple of minutes.
              schema:
                $ref: '#/components/schemas/error_too_many_requests'
      operationId: getApiV2WebhooksByWebhookTargetIdWebhookDeliveries
      x-operation-id-source: derived
  /api/v2/webhooks:
    post:
      summary: Creates a webhook
      security:
      - bearer_auth: []
      description: 'Creates a webhook that notifies the given `url` whenever one of the

        subscribed events occurs.


        Each delivery is signed so you can verify it originated from Hubflo. The

        request carries an `X-Hubflo-Signature` header containing the hex-encoded

        HMAC-SHA256 of the raw request body, computed with the webhook''s signing

        secret (returned as `secret` when the webhook is created). To verify a

        delivery, recompute the HMAC over the received body with your signing

        secret and compare it to the header value.


        Each delivery''s payload also includes a unique `webhook_delivery_id` (along

        with a `webhook_delivery_created_at` timestamp). Use it to deduplicate

        deliveries, since the same event may be delivered more than once.'
      tags:
      - Webhook
      parameters: []
      responses:
        '201':
          description: Webhook created from a legacy singular event_name
          headers:
            Content-Type:
              schema:
                type: string
              description: application/json; charset=utf-8
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
          content:
            application/json:
              examples:
                example:
                  value:
                    id: 15e32714-d549-4164-ab4e-c91104904308
                    event_names:
                    - contact_created
                    url: https://www.sample.com
                    active: true
                    created_at: '2026-07-17T13:10:12Z'
                    secret: vcPcBkE29GH69uwi6e4r5uJf
        '401':
          description: 'unauthorized: the Authorization header is missing or invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 401
                    title: Unauthorized
                    message: Invalid API token
              schema:
                $ref: '#/components/schemas/error_unauthorized'
        '422':
          description: 'unprocessable content: the resource can''t be created'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 422
                    title: Unprocessable Content
                    message: 'Validation failed: Event names must be filled in, Url must be filled in, Url is not a valid URL'
              schema:
                $ref: '#/components/schemas/error_unprocessable_content'
        '429':
          description: 'too many requests: the user has reached the rate limit'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 429
                    title: Too Many Requests
                    message: Rate limit reached. Please wait for a couple of minutes.
              schema:
                $ref: '#/components/schemas/error_too_many_requests'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                event_names:
                  type: array
                  items:
                    type: string
                    enum:
                    - authenticated_contact_added_to_workspace
                    - comment_created
                    - company_created
                    - company_updated
                    - contact_created
                    - contact_invited
                    - contact_signed_up
                    - contact_updated
                    - file_added_to_task
                    - file_uploaded
                    - file_uploaded_by_contact
                    - folder_created
                    - form_assignment_created
                    - form_submission_completed
                    - invoice_created
                    - invoice_issued
                    - invoice_overdue
                    - invoice_paid
                    - message_sent
                    - message_sent_by_contact
                    - project_stage_created
                    - project_stage_updated
                    - seal_submission_completed
                    - seal_submission_created
                    - task_completed
                    - task_completed_by_contact
                    - task_created
                    - task_created_by_contact
                    - task_overdue
                  description: The events the webhook subscribes to.
                  example:
                  - contact_created
                url:
                  type: string
                  example: https://www.webhook.com
              required:
              - url
        required: true
        description: Webhook attributes
      operationId: postApiV2Webhooks
      x-operation-id-source: derived
  /api/v2/webhooks/{id}:
    parameters:
    - name: id
      in: path
      required: true
      description: Webhook ID
      schema:
        type: string
    delete:
      summary: Deletes a webhook
      security:
      - bearer_auth: []
      tags:
      - Webhook
      responses:
        '204':
          description: Webhook deleted
          headers:
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
          content:
            application/json:
              examples:
                example:
                  value: ''
        '401':
          description: 'unauthorized: the Authorization header is missing or invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 401
                    title: Unauthorized
                    message: Invalid API token
              schema:
                $ref: '#/components/schemas/error_unauthorized'
        '404':
          description: 'not found: the resource is not found'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 404
                    title: Not Found
                    message: Resource not found
              schema:
                $ref: '#/components/schemas/error_not_found'
        '429':
          description: 'too many requests: the user has reached the rate limit'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 429
                    title: Too Many Requests
                    message: Rate limit reached. Please wait for a couple of minutes.
              schema:
                $ref: '#/components/schemas/error_too_many_requests'
      operationId: deleteApiV2WebhooksById
      x-operation-id-source: derived
components:
  schemas:
    error_not_found:
      description: A response describing a not found error
      type: object
      properties:
        status:
          type: integer
          example: 404
        title:
          type: string
          example: Not Found
        message:
          type: string
          example: Resource not found
      required:
      - status
      - title
      - message
    error_too_many_requests:
      description: A response describing a rate limit error
      type: object
      properties:
        status:
          type: integer
          example: 429
        title:
          type: string
          example: Too Many Requests
        message:
          type: string
          example: Rate limit reached. Please wait for a couple of minutes.
      required:
      - status
      - title
      - message
    error_unprocessable_content:
      description: A response describing a validation error
      type: object
      properties:
        status:
          type: integer
          example: 422
        title:
          type: string
          example: Unprocessable Content
        message:
          type: string
          example: 'Validation failed: Title can''t be blank'
      required:
      - status
      - title
      - message
    error_unauthorized:
      description: A response describing an authentication error
      type: object
      properties:
        status:
          type: integer
          example: 401
        title:
          type: string
          example: Unauthorized
        message:
          type: string
          example: API token not found
      required:
      - status
      - title
      - message
  securitySchemes:
    bearer_auth:
      type: http
      scheme: bearer
x-readme:
  explorer-enabled: true
  proxy-enabled: true