---
title: Webhooks
status: current
phase: 7
order: 6
---

# Webhooks

Deploy hooks through the API. Needs the `manage_webhooks` permission (agents and `management` keys have it). What Pluma sends and how to verify it: [Generic webhook deploy](../guides/deploy-webhook.md).

## List

`GET /api/v1/spaces/:space_id/webhooks`

## Create

`POST /api/v1/spaces/:space_id/webhooks`

```sh
curl -X POST https://pluma.so/api/v1/spaces/acton-estero/webhooks \
  -H "Authorization: Bearer $PLUMA_KEY" -H "Content-Type: application/json" \
  -d '{ "name": "Netlify", "kind": "netlify", "url": "https://api.netlify.com/build_hooks/abc123" }'
```

```json
{ "webhook": { "id": "1", "name": "Netlify", "kind": "netlify", "url": "https://api.netlify.com/build_hooks/abc123",
               "target": "production", "events": ["entry.published", "entry.unpublished", "content_type.changed"], "last_delivery": null },
  "secret": "whsec_…" }
```

- `kind`: `netlify`, `vercel` or `generic`. `events` is optional.
- `target`: `production` (default) rebuilds the live site when something is published. `preview` is for a [staging site](../guides/staging.md): it also rebuilds on every save (`entry.saved`), so drafts show up there.
- Events: `entry.published`, `entry.unpublished`, `content_type.changed`, `asset.replaced` (a file that something published uses got a new version) and `entry.saved`. A `production` hook listens to all but `entry.saved` unless you say otherwise; a `preview` hook always includes `entry.saved`.
- The `secret` to verify the signature is shown **only once**.
- The URL must be `https://` and public.

## Test

`POST /api/v1/spaces/:space_id/webhooks/:id/test`

Sends a test hook **right away** and returns what the destination answered:

```json
{ "delivery": { "id": "7", "status_code": 200, "ok": true, "response_ms": 184, "error": null, "test": true } }
```

A hook with a 2xx response checks off step 5 of the checklist.

## Delete

`DELETE /api/v1/spaces/:space_id/webhooks/:id`
