> ## Documentation Index
> Fetch the complete documentation index at: https://docs.remitflex.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create webhook endpoint

> Requires `webhooks:write` (or dashboard JWT). Returns `secret` (`whsec_…`) once.
URL must be HTTPS and must not resolve to a private IP.




## OpenAPI

````yaml /openapi.yaml post /webhooks
openapi: 3.1.0
info:
  title: Remitflex API
  version: 1.0.0
  description: >
    Programmatic access to Remitflex payment routes, fiat rates, customers, and
    transactions.


    **Dashboard:** Create API keys at https://dashboard.remitflex.io


    **Authentication:** Send your API key as `Authorization: Bearer
    rmf_live_...` or `rmf_test_...`.


    **Idempotency:** Mutating requests (`POST`, `PUT`, `PATCH`, `DELETE`)
    require an `Idempotency-Key` header when authenticated with an API key.
servers:
  - url: http://localhost:4000/v1
    description: Local development
  - url: https://api.remitflex.io/v1
    description: Production
security:
  - ApiKeyAuth: []
paths:
  /webhooks:
    post:
      tags:
        - Webhooks
      summary: Create webhook endpoint
      description: >
        Requires `webhooks:write` (or dashboard JWT). Returns `secret`
        (`whsec_…`) once.

        URL must be HTTPS and must not resolve to a private IP.
      operationId: createWebhookEndpoint
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - url
              properties:
                url:
                  type: string
                  format: uri
                  example: https://example.com/webhooks/remitflex
                description:
                  type: string
                  maxLength: 200
                  nullable: true
                events:
                  type: array
                  nullable: true
                  items:
                    type: string
                  description: Allowlist of event types. Empty/null = all events.
                enabled:
                  type: boolean
                  default: true
      responses:
        '201':
          description: Endpoint created (includes secret once)
      security:
        - ApiKeyAuth: []
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: true
      description: >-
        Unique key for safe retries on mutating API-key requests. Cached for 24
        hours per org, method, and path.
      schema:
        type: string
        maxLength: 255
        example: 7f3c2a1b-4e5d-6c7b-8a9f-0e1d2c3b4a5f
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      description: >
        API key created in the Remitflex Dashboard at dashboard.remitflex.io
        (`rmf_live_...` or `rmf_test_...`).

        Key management endpoints require a dashboard JWT and are not part of
        this reference.

````