> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textsetu.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a webhook endpoint

> Register an HTTPS URL to receive the events you subscribe it to. TextSetu generates a signing secret and returns it once.

**Constraints:**
- The `secret` is returned ONCE and cannot be retrieved later — store it before discarding the response.
- The URL must be publicly reachable — private, loopback and link-local addresses are rejected, and redirects are never followed.
- `eventTypes` must contain at least one type from `GET /webhook-event-types`.



## OpenAPI

````yaml /openapi/textsetu.json post /projects/{projectId}/webhooks
openapi: 3.1.0
info:
  title: TextSetu API
  version: 1.2.0
  description: >-
    Public REST API for TextSetu. Authenticate with a Personal Access Token
    (tsu_pat_…) or a project token (tsu_proj_…) via the `Authorization: Bearer
    <token>` header.


    **Authorization is permission-based.** Every token carries an explicit
    allow-list of RBAC permission keys (e.g. `translation_read`), and each
    endpoint declares the permission it requires (`x-permission`). A token's
    effective access is its underlying authority ∩ its allow-list — a PAT is
    further bounded by its owner's role-based permissions, so it can only
    narrow, never exceed, what the owner already has. A project token is bound
    to a single project. There are no coarse read/write/manage scopes.


    **Response envelope.** Every endpoint returns `{ "success": true, "data": …
    }` on success and `{ "success": false, "error": { "code", "message" } }` on
    failure.


    **Rate limit.** 600 requests/minute, keyed by token (or by IP when
    unauthenticated). Exceeding it returns 429 with the standard error envelope.
servers:
  - url: https://api.textsetu.com/api/v1
    description: Production
  - url: /api/v1
    description: This server (self-hosted / same-origin)
security:
  - bearerAuth: []
tags:
  - name: Projects
    description: >-
      Read project metadata — settings, key separator, and the
      approval/branching flags that shape how the other endpoints behave.
  - name: Languages
    description: >-
      List and manage a project's target languages. Each language is referenced
      by its BCP-47 code; the source language is flagged separately.
  - name: Translations
    description: >-
      Manage a project's translations: create, read, update, and delete
      translation keys — the identifiers your app looks up, carrying metadata
      (description, tags, screenshot) — and set the translated value for a key
      in a given language. Value writes honor the project's approval workflow —
      non-approver writes land as `pending_review`.
  - name: Stats
    description: >-
      Per-language completeness and approval progress for a project — the
      numbers behind the dashboard.
  - name: Import/Export
    description: >-
      Bulk-load source files into a project or export the current translations.
      Supports the same file formats as the web app.
  - name: Branches
    description: >-
      Work on translations in isolation and merge them back. Branch reads/writes
      mirror the main endpoints but stage changes as a diff until merge. See the
      [branching guide](/docs/guides/branches).
  - name: Glossary
    description: >-
      Manage term bases — approved terminology and its translations — and check
      a string against them. See the [glossary guide](/docs/guides/glossary).
  - name: Translation Memory
    description: >-
      Reusable translation stores. Fuzzy-match and concordance-search prior
      translations to reuse them. See the [translation memory
      guide](/docs/guides/translation-memory).
  - name: AI
    description: >-
      Machine-translate a project with the org's configured AI engine (brand
      voice, glossary/TM grounding, and an optional review pass). Runs
      asynchronously — start a run and poll the returned `jobId`.
  - name: Webhooks
    description: >-
      Get notified when a project's translations change, instead of polling.
      Register an HTTPS endpoint, subscribe it to the events you care about, and
      TextSetu POSTs a signed payload whenever one occurs. Payloads follow the
      [Standard Webhooks](https://www.standardwebhooks.com) spec — verify the
      `webhook-signature` header with any compatible library. Delivery is
      at-least-once and unordered, so treat `webhook-id` as an idempotency key.
      Failed deliveries are retried five times over roughly seven hours, and
      every attempt is inspectable and replayable via the delivery log.
  - name: Meta
    description: Service-level and cross-cutting endpoints.
paths:
  /projects/{projectId}/webhooks:
    post:
      tags:
        - Webhooks
      summary: Create a webhook endpoint
      description: >-
        Register an HTTPS URL to receive the events you subscribe it to.
        TextSetu generates a signing secret and returns it once.


        **Constraints:**

        - The `secret` is returned ONCE and cannot be retrieved later — store it
        before discarding the response.

        - The URL must be publicly reachable — private, loopback and link-local
        addresses are rejected, and redirects are never followed.

        - `eventTypes` must contain at least one type from `GET
        /webhook-event-types`.
      parameters:
        - name: projectId
          in: path
          required: true
          schema:
            type: string
          description: Project id (UUID) or id-embedded path slug.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                url:
                  type: string
                  minLength: 1
                  maxLength: 2048
                  format: uri
                description:
                  anyOf:
                    - type: string
                      maxLength: 500
                    - type: 'null'
                eventTypes:
                  minItems: 1
                  maxItems: 10
                  type: array
                  items:
                    type: string
                    enum:
                      - translation_key.created
                      - translation_key.updated
                      - translation_key.deleted
                      - translation_value.updated
                      - branch.created
                      - branch.merged
                      - import.completed
                      - export.completed
                      - language.added
                      - language.removed
                includeAiGenerated:
                  default: false
                  type: boolean
              required:
                - url
                - eventTypes
      responses:
        '201':
          description: The created endpoint and its signing secret.
          content:
            application/json:
              schema:
                type: object
                required:
                  - success
                  - data
                properties:
                  success:
                    type: boolean
                    const: true
                  data:
                    type: object
                    properties:
                      endpoint:
                        type: object
                        properties:
                          id:
                            type: string
                            description: Endpoint id.
                            examples:
                              - 9f2c…
                          url:
                            type: string
                            description: The HTTPS URL that receives the POST.
                            examples:
                              - https://example.com/webhooks/textsetu
                          description:
                            anyOf:
                              - type: string
                              - type: 'null'
                            description: Free-text note about what consumes this endpoint.
                          eventTypes:
                            type: array
                            items:
                              type: string
                            description: >-
                              Event types this endpoint is subscribed to. Only
                              these are delivered — there is no implicit 'all',
                              so a newly added event type is never delivered
                              until you subscribe to it.
                            examples:
                              - - translation_key.created
                                - branch.merged
                          status:
                            type: string
                            enum:
                              - enabled
                              - disabled
                              - auto_disabled
                            description: >-
                              `auto_disabled` means TextSetu turned it off after
                              repeated delivery failures; PATCH `status:
                              "enabled"` to resume.
                          secretPrefix:
                            type: string
                            description: >-
                              Non-secret display prefix of the signing secret.
                              The full secret is returned only when the endpoint
                              is created or its secret rotated.
                            examples:
                              - whsec_a1b2c3
                          includeAiGenerated:
                            type: boolean
                            description: >-
                              Whether AI-generated changes are delivered. Off by
                              default — a bulk AI run can produce thousands of
                              value updates.
                          consecutiveFailures:
                            type: integer
                            description: >-
                              Consecutive failed deliveries; reset to 0 on any
                              success.
                          lastSuccessAt:
                            anyOf:
                              - type: string
                              - type: 'null'
                            description: ISO 8601 timestamp.
                          lastFailureAt:
                            anyOf:
                              - type: string
                              - type: 'null'
                            description: ISO 8601 timestamp.
                          lastError:
                            anyOf:
                              - type: string
                              - type: 'null'
                            description: Reason for the last failure.
                          createdAt:
                            type: string
                            description: ISO 8601 timestamp.
                          updatedAt:
                            type: string
                            description: ISO 8601 timestamp.
                        required:
                          - id
                          - url
                          - description
                          - eventTypes
                          - status
                          - secretPrefix
                          - includeAiGenerated
                          - consecutiveFailures
                          - lastSuccessAt
                          - lastFailureAt
                          - lastError
                          - createdAt
                          - updatedAt
                        additionalProperties: false
                      secret:
                        type: string
                        description: The signing secret, shown only here.
                        examples:
                          - whsec_MfKQ9r8G…
                    required:
                      - endpoint
                      - secret
                    additionalProperties: false
        '400':
          description: Invalid URL, blocked address, or no valid event types selected.
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        API token: tsu_pat_… (PAT) or tsu_proj_… (project token). The token's
        granted RBAC permissions determine access; see each operation's
        `x-permission`.

````