# Create a webhook endpoint
Source: https://www.desktopaccountingapi.com/docs/api/reference/operations/webhookendpointscreate/

`POST https://api.desktopaccountingapi.com/v1/webhook-endpoints`

Operation ID: `webhookEndpoints.create`. Tag: Webhooks.

Registers an HTTPS endpoint for events of this project. The response contains the signing secret once. Deliveries are signed with the [Standard Webhooks](https://www.standardwebhooks.com/) scheme (`webhook-id`, `webhook-timestamp`, `webhook-signature`), retried on failure for about 27 hours (after 5 s, 5 min, 30 min, 2 h, 5 h, 10 h and 10 h) and recorded in the delivery log. A project can have up to 20 endpoints.

Authentication: `Authorization: Bearer <secret key>`.

## Headers

- `Idempotency-Key` (string): Makes a write safe to retry. Repeating a key with the same request attaches to or replays the original instead of creating a second one. 1–255 printable ASCII characters, retained 7 days. Reusing a key with a different request returns `422 IDEMPOTENCY_KEY_REUSED`. 1–255 characters; example `6f1c2a0e-1f7e-4c55-9a7a-0b2d2c9e3a10`.

## Request body (application/json, required)

- `url` (string (uri), required): HTTPS URL on a public DNS name and the default port. IP addresses, internal names and redirects are not allowed. max 2048 characters; example `https://example.com/webhooks/desktop-accounting`.
- `eventTypes` (array of string, required): Event types to deliver. At least one. 1–7 items.
- `description` (string): Your note about the endpoint, up to 500 characters. max 500 characters; example `Production sync worker`.
- `enabled` (boolean): Deliver events. Default `true`. default `true`.
- `includeSyncRequests` (boolean): Also deliver request events for synchronous calls whose caller already received the result. Default `false`: synchronous requests produce events only when the caller did not get the final result (timeout after sending, disconnect) or the outcome is unknown. default `false`.

Minimal example:

```json
{
  "url": "https://example.com/webhooks/desktop-accounting",
  "eventTypes": [
    "request.succeeded"
  ]
}
```

## Responses

### 201

The created endpoint with its signing secret.

Body (application/json): object (WebhookEndpoint).

### Errors

Every error body is the error object described at https://www.desktopaccountingapi.com/docs/errors/.

- `400`: The request is invalid. Codes: `UNKNOWN_HEADER`, `INVALID_JSON`, `INVALID_PARAMETER`, `UNKNOWN_PARAMETER`, `IDEMPOTENCY_KEY_INVALID`.
- `401`: The API key is missing or invalid. Codes: `API_KEY_MISSING`, `API_KEY_INVALID`.
- `403`: The operation is not permitted. Codes: `API_KEY_READ_ONLY`.
- `422`: The request is well formed but cannot be processed. Codes: `IDEMPOTENCY_KEY_REUSED`, `WEBHOOK_ENDPOINT_LIMIT_REACHED`.
- `429`: Too many requests. Codes: `RATE_LIMITED`.
- `500`: Unexpected server error. Codes: `INTERNAL_ERROR`.
- `503`: QuickBooks Desktop or the service is not available. Codes: `SERVICE_UNAVAILABLE`.
