Boltly Boltly / Docs
Docs / API Reference / Webhook Subscriptions

Webhook Subscriptions

Subscribe HTTPS endpoints to real-time message events. Every delivery is signed with an HMAC SHA-256 signature sent in the X-Webhook-Signature header — verify it against your subscription secret before trusting the payload.

POST /v1/webhook-subscriptions

Create subscription

Subscribe an HTTPS endpoint to receive event notifications.

Parameters

url string required

HTTPS endpoint that will receive event payloads.

events array required

Event types to subscribe to. One or more of: message.received, message.sent, message.delivered, message.read, message.failed.

description string

Optional description for this subscription. Max 500 characters.

Request

cURL
curl -X POST https://api.boltly.online/v1/webhook-subscriptions \
  -H "X-API-Key: $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://example.com/webhooks/boltly",
    "events": ["message.received", "message.delivered"],
    "description": "Production event listener"
  }'

Response

JSON
{
  "data": {
    "id": "9b2e6c1a-...",
    "url": "https://example.com/webhooks/boltly",
    "events": ["message.received", "message.delivered"],
    "is_active": true,
    "description": "Production event listener",
    "created_by": "4f1a8d2b-...",
    "created_at": "2026-04-03T12:00:00Z",
    "updated_at": "2026-04-03T12:00:00Z"
  }
}

GET /v1/webhook-subscriptions

List subscriptions

Retrieve all webhook subscriptions for your organization.

Request

cURL
curl https://api.boltly.online/v1/webhook-subscriptions \
  -H "X-API-Key: $API_KEY"

Response

JSON
{
  "data": {
    "webhooks": [
      {
        "id": "9b2e6c1a-...",
        "url": "https://example.com/webhooks/boltly",
        "events": ["message.received", "message.delivered"],
        "is_active": true,
        "created_at": "2026-04-03T12:00:00Z",
        "updated_at": "2026-04-03T12:00:00Z"
      }
    ]
  }
}

POST /v1/webhook-subscriptions/{id}/test

Test webhook

Send a signed test event to the subscription's endpoint to verify it is reachable and validating signatures correctly.

Parameters

id string required

Webhook subscription ID.

Request

cURL
curl -X POST https://api.boltly.online/v1/webhook-subscriptions/9b2e6c1a-.../test \
  -H "X-API-Key: $API_KEY"

Response

JSON
{
  "data": {
    "delivered": true,
    "status_code": 200,
    "event": {
      "id": "evt_test_01H...",
      "type": "message.received",
      "organization_id": "4f1a8d2b-...",
      "created_at": "2026-04-03T12:00:00Z",
      "data": { "test": true }
    }
  }
}

DELETE /v1/webhook-subscriptions/{id}

Delete subscription

Permanently delete a webhook subscription. The endpoint stops receiving events immediately.

Parameters

id string required

Webhook subscription ID.

Request

cURL
curl -X DELETE https://api.boltly.online/v1/webhook-subscriptions/9b2e6c1a-... \
  -H "X-API-Key: $API_KEY"

Response

JSON
{
  "data": { "deleted": true }
}