# Update a webhook endpoint
Source: https://www.desktopaccountingapi.com/docs/api/reference/operations/webhookendpointsupdate/

`POST https://api.desktopaccountingapi.com/v1/webhook-endpoints/{id}`

Operation ID: `webhookEndpoints.update`. Tag: Webhooks.

Updates the URL, event types, description, `enabled` or `includeSyncRequests`. Omitted fields are unchanged. Re-enabling an endpoint that was disabled after failed deliveries clears `disabledReason`.

Authentication: `Authorization: Bearer <secret key>`.

## Path parameters

- `id` (string, required): Unique identifier for the webhook endpoint. example `whe_01j9x4m6v4c8k2t7q0r5s3w1zg`.

## Headers

- `Idempotency-Key` (string): Makes a write safe to retry. Repeating a key with the same request attaches to or replays the original instead of creating a second one. 1–255 printable ASCII characters, retained 7 days. Reusing a key with a different request returns `422 IDEMPOTENCY_KEY_REUSED`. 1–255 characters; example `6f1c2a0e-1f7e-4c55-9a7a-0b2d2c9e3a10`.

## Request body (application/json, required)

- `url` (string (uri)): HTTPS URL on a public DNS name and the default port. IP addresses, internal names and redirects are not allowed. max 2048 characters; example `https://example.com/webhooks/desktop-accounting`.
- `eventTypes` (array of string): Event types to deliver. At least one. 1–7 items.
- `description` (string, nullable): Your note about the endpoint, up to 500 characters. max 500 characters; example `Production sync worker`.
- `enabled` (boolean): Turn delivery on or off. Enabling clears `disabledReason`.
- `includeSyncRequests` (boolean): Also deliver request events for synchronous calls whose caller already received the result. Default `false`: synchronous requests produce events only when the caller did not get the final result (timeout after sending, disconnect) or the outcome is unknown.

Minimal example:

```json
{}
```

## Responses

### 200

The updated endpoint.

Body (application/json): object (WebhookEndpoint).

- `id` (string, required): Unique identifier for the webhook endpoint. example `whe_01j9x4m6v4c8k2t7q0r5s3w1zg`.
- `objectType` (string, required): Always `webhook_endpoint`. one of `webhook_endpoint`.
- `createdAt` (string (date-time), required): When the endpoint was created. UTC, ISO 8601 with milliseconds. example `2026-10-05T16:03:59.002Z`.
- `projectId` (string, required): Unique identifier for the project. example `proj_01j9x4m6v4c8k2t7q0r5s3w1zf`.
- `url` (string, required): Where events are delivered.
- `description` (string, nullable, required): Your note about the endpoint.
- `eventTypes` (array of string, required): Subscribed event types.
- `enabled` (boolean, required): Whether events are delivered.
- `disabledReason` (string, nullable, required): Why the endpoint was disabled automatically (5 days of failed deliveries), or `null`.
- `includeSyncRequests` (boolean, required): Whether request events of synchronous calls whose caller received the result are delivered.
- `secretRotatedAt` (string, nullable, required): When the signing secret was last rotated. UTC, ISO 8601.
- `previousSecretExpiresAt` (string, nullable, required): Until when deliveries also carry a signature made with the previous secret. UTC, ISO 8601.

### Errors

Every error body is the error object described at https://www.desktopaccountingapi.com/docs/errors/.

- `400`: The request is invalid. Codes: `UNKNOWN_HEADER`, `INVALID_JSON`, `INVALID_PARAMETER`, `UNKNOWN_PARAMETER`, `IDEMPOTENCY_KEY_INVALID`.
- `401`: The API key is missing or invalid. Codes: `API_KEY_MISSING`, `API_KEY_INVALID`.
- `403`: The operation is not permitted. Codes: `API_KEY_READ_ONLY`.
- `404`: The object does not exist in this project. Codes: `RESOURCE_MISSING`.
- `422`: The request is well formed but cannot be processed. Codes: `IDEMPOTENCY_KEY_REUSED`.
- `429`: Too many requests. Codes: `RATE_LIMITED`.
- `500`: Unexpected server error. Codes: `INTERNAL_ERROR`.
- `503`: QuickBooks Desktop or the service is not available. Codes: `SERVICE_UNAVAILABLE`.
