Watch
Register a webhook destination
/data-api/v2/watch/endpoints- Scope
- directory:read
- Freshness
- catalog read
- Group
- Watch
- Platforms
- any
What this endpoint answers
Registers an https URL to receive change notifications and mints its signing secret. The secret is returned exactly once, in this response, and is never readable again. The endpoint starts in 'pending' and receives nothing until it is verified.
This is a catalog read: it is served from the CRM Solid database in milliseconds, costs one budget unit, and reports how old the reading is in meta.cache_age_s. It needs the directory:read scope (Directory): Read the account and channel catalog across all seven platforms.
Good to know
- Store the secret now. It is not recoverable, and rotating it means deleting the endpoint and registering it again.
- A maximum of 10 endpoints per account.
- Registering a URL that is already registered on this account returns 422 rather than reissuing the secret, which would break the integration already using it.
- https only. The signature proves a payload came from us; it does not keep anyone else from reading it in transit.
Parameters
This endpoint takes no path or query parameters.
Request body
urlstringrequiredhttps endpoint that will receive POSTs. Must be publicly reachable; loopback and private ranges are refused.
descriptionstringoptionalYour own label for this destination.
{
"url": "https://hooks.example.com/playersells"
}
Call it
Authenticate with a bearer token or the x-api-key header. Keys are server-to-server credentials. Never embed one in front-end code - call the API from your own backend and forward the result.
curl -X POST "https://crmsolid.com/data-api/v2/watch/endpoints" \
-H "Authorization: Bearer psk_live_..." \
-H "Content-Type: application/json" \
-d '{"url":"https://hooks.example.com/playersells"}'
const res = await fetch("https://crmsolid.com/data-api/v2/watch/endpoints", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.CRM_SOLID_DATA_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"url": "https://hooks.example.com/playersells"
}),
});
if (!res.ok) {
const { error } = await res.json();
throw new Error(`${error.code}: ${error.message} (${error.request_id})`);
}
const { data, meta } = await res.json();
import json
import os
import requests
body = json.loads("""
{
"url": "https://hooks.example.com/playersells"
}
""")
res = requests.post(
"https://crmsolid.com/data-api/v2/watch/endpoints",
headers={"Authorization": f"Bearer {os.environ['CRM_SOLID_DATA_API_KEY']}"},
json=body,
timeout=30,
)
res.raise_for_status()
payload = res.json()
data, meta = payload["data"], payload["meta"]
Keys look like psk_live_... for production keys, psk_test_... for test keys and are minted in the panel.
What comes back
Success is { data, meta }. Failure is { error: { code, message, request_id } }. The body below is the spec's own example: the values in it are illustrative readings, not live numbers.
- Id
- 9f1c2b7e-4d3a-4c88-9a10-2f6b5e0d7c31
- Url
- https://hooks.example.com/playersells
- Description
- production receiver
- Status
- pending
- Echo verified
- no
- Health consecutive failures
- 0
- Health last success at
- 8/31/2026, 11:00:04 AM
- Created at
- 8/31/2026, 9:12:00 AM
- Secret
- whsec_Q2hhbmdlTWVJQW1BbkV4YW1wbGU
- Verification token
- whtok_dGhpc0lzQW5FeGFtcGxl
{
"data": {
"id": "9f1c2b7e-4d3a-4c88-9a10-2f6b5e0d7c31",
"url": "https://hooks.example.com/playersells",
"description": "production receiver",
"status": "pending",
"verified_at": null,
"echo_verified": false,
"health": {
"consecutive_failures": 0,
"last_success_at": "2026-08-31T11:00:04.000Z",
"last_failure_at": null,
"last_error": null,
"disabled_at": null,
"disabled_reason": null
},
"created_at": "2026-08-31T09:12:00.000Z",
"secret": "whsec_Q2hhbmdlTWVJQW1BbkV4YW1wbGU",
"verification_token": "whtok_dGhpc0lzQW5FeGFtcGxl"
},
"meta": {
"request_id": "req_9f2c41a8b3d5",
"generated_at": "2026-08-23T09:14:02.317Z",
"took_ms": 42
}
}
The meta block
request_idstringrequiredUnique id for this request. Quote it in a support ticket.
generated_atstringrequiredServer time the response was produced.
took_msintegerrequiredMilliseconds spent server-side.
pagePageoptionalsourcestringoptionalWhich backend served the payload, for endpoints with more than one.
cache_age_sintegeroptionalAge of the underlying data in seconds. 0 for live reads.
When it fails
POST /watch/endpoints documents 7 failure statuses. Branch on error.code, which is stable and enumerated; message is prose and may change.
- 401Unauthorized
unauthorized | invalid_keyNo key was presented, or the key is unknown, revoked or expired.
- 402PaymentRequired
payment_required | subscription_inactiveThe key is valid but the plan behind it cannot serve the call: the included requests are spent and overage is switched off, capped or unfunded (payment_required), or the billing period lapsed and was not renewed (subscription_inactive). Retrying does not help; paying does. The X-Plan-* headers on this response say how far past the line you are.
Carries X-Plan, X-Plan-Limit, X-Plan-Overage, X-Plan-Period-End, X-Plan-Remaining.
- 403Forbidden
forbidden_scope | forbidden_ipThe key is valid but not allowed to make this call: it lacks the scope, or the request came from an address outside the key's allowlist.
- 422InvalidRequest
invalid_requestA parameter is malformed, out of range or mutually exclusive with another. `details` names the offending fields.
- 429RateLimited
rate_limited | quota_exceededEither the burst ceiling for the current minute or the daily quota is spent. Distinguish with the code: rate_limited clears within the minute, quota_exceeded does not clear until 00:00 UTC.
Carries Retry-After, X-Quota-Limit, X-Quota-Remaining, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, X-Request-Id.
- 500InternalError
internal_errorSomething failed on our side. Internals are never leaked; quote the request id.
- 503Unavailable
upstream_timeout | upstream_error | not_configuredThe request could not be served right now. BRANCH ON error.code, not on the status: 'upstream_timeout' means a source was too slow (this is what a catalog query hitting its 15-second statement timeout returns, so it is reachable from any endpoint that reads the corpus, not only the live-scrape ones) and the same call is worth retrying with backoff - narrowing it with a smaller limit, a filtered scope or a less popular account makes it far less likely; 'upstream_error' means a source was unreachable, so back off further; 'not_configured' means the capability has no backing service in this deployment, and retrying will never help.
Every response carries X-Request-Id and meta.request_id. Quote it in support requests.
Coverage and limits
This endpoint is not platform-specific. Rate limits come from the tier on your key.
| Tier | Requests a minute | Requests a day | Live reads a minute |
|---|---|---|---|
| free | 30 | 1,000 | 5 |
| standard | 120 | 25,000 | 20 |
| pro | 600 | 250,000 | 60 |
| unlimited | 6,000 | 10,000,000 | 600 |
This call only draws on the ordinary per-minute and per-day columns. Every response reports where you stand in X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset and the X-Plan headers.
Start calling it
A key takes a minute to mint in the panel, no card. The reference covers authentication, the envelope, scopes, rate limits and every error code in one page.
Reference path: /data-api/reference/watch-endpoints-create