Watch

Register a webhook destination

POST/data-api/v2/watch/endpoints
Scope
directory:read
Freshness
catalog read
Group
Watch
Platforms
any

What this endpoint answers

Registers an https URL to receive change notifications and mints its signing secret. The secret is returned exactly once, in this response, and is never readable again. The endpoint starts in 'pending' and receives nothing until it is verified.

This is a catalog read: it is served from the CRM Solid database in milliseconds, costs one budget unit, and reports how old the reading is in meta.cache_age_s. It needs the directory:read scope (Directory): Read the account and channel catalog across all seven platforms.

Good to know

  • Store the secret now. It is not recoverable, and rotating it means deleting the endpoint and registering it again.
  • A maximum of 10 endpoints per account.
  • Registering a URL that is already registered on this account returns 422 rather than reissuing the secret, which would break the integration already using it.
  • https only. The signature proves a payload came from us; it does not keep anyone else from reading it in transit.

Parameters

This endpoint takes no path or query parameters.

Request body

  • urlstringrequired

    https endpoint that will receive POSTs. Must be publicly reachable; loopback and private ranges are refused.

  • descriptionstringoptional

    Your own label for this destination.

Example request body
{
  "url": "https://hooks.example.com/playersells"
}

Call it

Authenticate with a bearer token or the x-api-key header. Keys are server-to-server credentials. Never embed one in front-end code - call the API from your own backend and forward the result.

curl
curl -X POST "https://crmsolid.com/data-api/v2/watch/endpoints" \
  -H "Authorization: Bearer psk_live_..." \
  -H "Content-Type: application/json" \
  -d '{"url":"https://hooks.example.com/playersells"}'
JavaScript
const res = await fetch("https://crmsolid.com/data-api/v2/watch/endpoints", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.CRM_SOLID_DATA_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "url": "https://hooks.example.com/playersells"
  }),
});

if (!res.ok) {
  const { error } = await res.json();
  throw new Error(`${error.code}: ${error.message} (${error.request_id})`);
}

const { data, meta } = await res.json();
Python
import json
import os

import requests

body = json.loads("""
{
  "url": "https://hooks.example.com/playersells"
}
""")

res = requests.post(
    "https://crmsolid.com/data-api/v2/watch/endpoints",
    headers={"Authorization": f"Bearer {os.environ['CRM_SOLID_DATA_API_KEY']}"},
    json=body,
    timeout=30,
)
res.raise_for_status()

payload = res.json()
data, meta = payload["data"], payload["meta"]

Keys look like psk_live_... for production keys, psk_test_... for test keys and are minted in the panel.

What comes back

Success is { data, meta }. Failure is { error: { code, message, request_id } }. The body below is the spec's own example: the values in it are illustrative readings, not live numbers.

Id
9f1c2b7e-4d3a-4c88-9a10-2f6b5e0d7c31
Url
https://hooks.example.com/playersells
Description
production receiver
Status
pending
Echo verified
no
Health consecutive failures
0
Health last success at
8/31/2026, 11:00:04 AM
Created at
8/31/2026, 9:12:00 AM
Secret
whsec_Q2hhbmdlTWVJQW1BbkV4YW1wbGU
Verification token
whtok_dGhpc0lzQW5FeGFtcGxl
200 POST /watch/endpoints
{
  "data": {
    "id": "9f1c2b7e-4d3a-4c88-9a10-2f6b5e0d7c31",
    "url": "https://hooks.example.com/playersells",
    "description": "production receiver",
    "status": "pending",
    "verified_at": null,
    "echo_verified": false,
    "health": {
      "consecutive_failures": 0,
      "last_success_at": "2026-08-31T11:00:04.000Z",
      "last_failure_at": null,
      "last_error": null,
      "disabled_at": null,
      "disabled_reason": null
    },
    "created_at": "2026-08-31T09:12:00.000Z",
    "secret": "whsec_Q2hhbmdlTWVJQW1BbkV4YW1wbGU",
    "verification_token": "whtok_dGhpc0lzQW5FeGFtcGxl"
  },
  "meta": {
    "request_id": "req_9f2c41a8b3d5",
    "generated_at": "2026-08-23T09:14:02.317Z",
    "took_ms": 42
  }
}

The meta block

  • request_idstringrequired

    Unique id for this request. Quote it in a support ticket.

  • generated_atstringrequired

    Server time the response was produced.

  • took_msintegerrequired

    Milliseconds spent server-side.

  • pagePageoptional
  • sourcestringoptional

    Which backend served the payload, for endpoints with more than one.

  • cache_age_sintegeroptional

    Age of the underlying data in seconds. 0 for live reads.

When it fails

POST /watch/endpoints documents 7 failure statuses. Branch on error.code, which is stable and enumerated; message is prose and may change.

  • 401Unauthorizedunauthorized | invalid_key

    No key was presented, or the key is unknown, revoked or expired.

  • 402PaymentRequiredpayment_required | subscription_inactive

    The key is valid but the plan behind it cannot serve the call: the included requests are spent and overage is switched off, capped or unfunded (payment_required), or the billing period lapsed and was not renewed (subscription_inactive). Retrying does not help; paying does. The X-Plan-* headers on this response say how far past the line you are.

    Carries X-Plan, X-Plan-Limit, X-Plan-Overage, X-Plan-Period-End, X-Plan-Remaining.

  • 403Forbiddenforbidden_scope | forbidden_ip

    The key is valid but not allowed to make this call: it lacks the scope, or the request came from an address outside the key's allowlist.

  • 422InvalidRequestinvalid_request

    A parameter is malformed, out of range or mutually exclusive with another. `details` names the offending fields.

  • 429RateLimitedrate_limited | quota_exceeded

    Either the burst ceiling for the current minute or the daily quota is spent. Distinguish with the code: rate_limited clears within the minute, quota_exceeded does not clear until 00:00 UTC.

    Carries Retry-After, X-Quota-Limit, X-Quota-Remaining, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, X-Request-Id.

  • 500InternalErrorinternal_error

    Something failed on our side. Internals are never leaked; quote the request id.

  • 503Unavailableupstream_timeout | upstream_error | not_configured

    The request could not be served right now. BRANCH ON error.code, not on the status: 'upstream_timeout' means a source was too slow (this is what a catalog query hitting its 15-second statement timeout returns, so it is reachable from any endpoint that reads the corpus, not only the live-scrape ones) and the same call is worth retrying with backoff - narrowing it with a smaller limit, a filtered scope or a less popular account makes it far less likely; 'upstream_error' means a source was unreachable, so back off further; 'not_configured' means the capability has no backing service in this deployment, and retrying will never help.

Every response carries X-Request-Id and meta.request_id. Quote it in support requests.

Coverage and limits

This endpoint is not platform-specific. Rate limits come from the tier on your key.

TierRequests a minuteRequests a dayLive reads a minute
free301,0005
standard12025,00020
pro600250,00060
unlimited6,00010,000,000600

This call only draws on the ordinary per-minute and per-day columns. Every response reports where you stand in X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset and the X-Plan headers.

Start calling it

A key takes a minute to mint in the panel, no card. The reference covers authentication, the envelope, scopes, rate limits and every error code in one page.

Reference path: /data-api/reference/watch-endpoints-create

We value your privacy

We use cookies to improve our site, analyze traffic, and personalize ads. You can accept all, reject non-essential, or customize your choices. Read our Cookie Policy.