Create a webhook endpoint
POST /v1/webhooks
Registers a URL to receive events. Same rules as the console: https only, a publicly reachable host, known event types, at most 5 endpoints per account. The response includes secret, the signing secret: this is the only time the API returns it. Recorded in the audit log as webhook.created. Scope: webhooks:write.
Send your API key as a bearer token: Authorization: Bearer ssms_sk_.... Test keys run this endpoint against the sandbox; see Authentication for key modes and scopes.
Request body
JSON (Content-Type: application/json).
| Field | Type | Required | Description |
|---|---|---|---|
url | string (uri) | Yes | Example: https://example.com/webhooks/simplesms. |
events | * or array of string | No | Event types to receive. Omit, or send "*" or [], for every event. An unknown type is a 400. |
description | string | No | At most 120 characters. |
Responses
| Status | Meaning | Body |
|---|---|---|
| 201 | The endpoint, with its signing secret (shown once) | WebhookEndpoint |
| 401 | Missing, malformed, or revoked API key | Error |
| 402 | Billable live calls only: the prepaid credit balance cannot cover the call (insufficient_credits); nothing was done or charged | Error |
| 429 | Rate limit or quota exceeded | Error |
201: WebhookEndpoint fields
| Field | Type | Description |
|---|---|---|
id | string | Example: we_a1B2c3D4e5F6. |
object | webhook_endpoint | |
url | string (uri) | |
events | * or array of string | |
active | boolean | |
description | string | Nullable. |
created_at | string (date-time) | |
secret | string | Example: whsec_a1B2c3D4e5F6g7H8a1B2c3D4e5F6g7H8. |
Errors
| Status | When |
|---|---|
| 401 | Missing, malformed, or revoked API key |
| 402 | Billable live calls only: the prepaid credit balance cannot cover the call (insufficient_credits); nothing was done or charged |
| 429 | Rate limit or quota exceeded |
Every error has the same JSON shape, and request_id matches the X-Request-Id response header. Errors lists every code and what to do about it.
{
"error": {
"code": "invalid_request",
"message": "What went wrong, in plain words.",
"param": "the_field",
"request_id": "req_a1B2c3D4e5F6g7H8"
}
}Examples
curl
curl -X POST "https://api.joinsimplesms.com/v1/webhooks" \
-H "Authorization: Bearer $SIMPLESMS_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"url": "https://example.com/webhooks/simplesms"
}'Node.js
The Node.js SDK does not wrap this endpoint yet; call it with fetch.
const res = await fetch('https://api.joinsimplesms.com/v1/webhooks', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.SIMPLESMS_API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"url": "https://example.com/webhooks/simplesms"
}),
});
if (!res.ok) throw new Error((await res.json()).error.message);
const data = await res.json();Python
The Python SDK does not wrap this endpoint yet; call it over HTTP.
import json, os, urllib.request
req = urllib.request.Request(
"https://api.joinsimplesms.com/v1/webhooks",
method="POST",
headers={
"Authorization": f"Bearer {os.environ['SIMPLESMS_API_KEY']}",
"Content-Type": "application/json",
},
data=json.dumps({
"url": "https://example.com/webhooks/simplesms"
}).encode(),
)
with urllib.request.urlopen(req) as res:
data = json.load(res)