Create a webhook subscription.
curl --request POST \
--url https://sandbox.api.byzantine.fi/v1/webhooks/subscriptions \
--header 'Content-Type: application/json' \
--header 'X-Pubkey: <x-pubkey>' \
--header 'X-Pubkey, X-Timestamp, X-Signature: <api-key>' \
--header 'X-Signature: <x-signature>' \
--header 'X-Timestamp: <x-timestamp>' \
--data '
{
"url": "<string>",
"name": "<string>",
"enabled": true,
"eventTypes": [
"<string>"
]
}
'import requests
url = "https://sandbox.api.byzantine.fi/v1/webhooks/subscriptions"
payload = {
"url": "<string>",
"name": "<string>",
"enabled": True,
"eventTypes": ["<string>"]
}
headers = {
"X-Pubkey": "<x-pubkey>",
"X-Timestamp": "<x-timestamp>",
"X-Signature": "<x-signature>",
"X-Pubkey, X-Timestamp, X-Signature": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-Pubkey': '<x-pubkey>',
'X-Timestamp': '<x-timestamp>',
'X-Signature': '<x-signature>',
'X-Pubkey, X-Timestamp, X-Signature': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({url: '<string>', name: '<string>', enabled: true, eventTypes: ['<string>']})
};
fetch('https://sandbox.api.byzantine.fi/v1/webhooks/subscriptions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"subscription": {
"id": "550e8400-e29b-41d4-a716-446655440000",
"integratorId": "550e8400-e29b-41d4-a716-446655440000",
"url": "<string>",
"enabled": true,
"eventTypes": "<unknown>",
"endpointSafetyMetadata": "<unknown>",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"name": "<string>",
"activeSigningKeyId": "550e8400-e29b-41d4-a716-446655440000"
},
"publicKey": "<string>",
"algorithm": "<string>"
}{
"error": "Resource not found",
"status": 404
}Webhooks
Create a webhook subscription.
Registers an integrator-owned webhook endpoint, validates its HTTPS/DNS safety metadata, creates an active P-256 signing key, and returns the public verification key for future deliveries.
POST
/
v1
/
webhooks
/
subscriptions
Create a webhook subscription.
curl --request POST \
--url https://sandbox.api.byzantine.fi/v1/webhooks/subscriptions \
--header 'Content-Type: application/json' \
--header 'X-Pubkey: <x-pubkey>' \
--header 'X-Pubkey, X-Timestamp, X-Signature: <api-key>' \
--header 'X-Signature: <x-signature>' \
--header 'X-Timestamp: <x-timestamp>' \
--data '
{
"url": "<string>",
"name": "<string>",
"enabled": true,
"eventTypes": [
"<string>"
]
}
'import requests
url = "https://sandbox.api.byzantine.fi/v1/webhooks/subscriptions"
payload = {
"url": "<string>",
"name": "<string>",
"enabled": True,
"eventTypes": ["<string>"]
}
headers = {
"X-Pubkey": "<x-pubkey>",
"X-Timestamp": "<x-timestamp>",
"X-Signature": "<x-signature>",
"X-Pubkey, X-Timestamp, X-Signature": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-Pubkey': '<x-pubkey>',
'X-Timestamp': '<x-timestamp>',
'X-Signature': '<x-signature>',
'X-Pubkey, X-Timestamp, X-Signature': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({url: '<string>', name: '<string>', enabled: true, eventTypes: ['<string>']})
};
fetch('https://sandbox.api.byzantine.fi/v1/webhooks/subscriptions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"subscription": {
"id": "550e8400-e29b-41d4-a716-446655440000",
"integratorId": "550e8400-e29b-41d4-a716-446655440000",
"url": "<string>",
"enabled": true,
"eventTypes": "<unknown>",
"endpointSafetyMetadata": "<unknown>",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"name": "<string>",
"activeSigningKeyId": "550e8400-e29b-41d4-a716-446655440000"
},
"publicKey": "<string>",
"algorithm": "<string>"
}{
"error": "Resource not found",
"status": 404
}Authorizations
Headers
Integrator's ECDSA public key (P-256 curve, compressed SEC1 format). Example: 0x038fedef7c12f93bbf342ad8943b7a825a3b41f61c9dc118b2c718efebabbf62fd
Unix timestamp in seconds (UTC). Must be within tolerance window (1 minute) to prevent replay attacks. Example: 1760375826
ECDSA signature (DER-encoded, hex with 0x prefix). Signs the message: {timestamp}{METHOD}{path_and_query}{json_body}. Example: 0x3045022100...

