Dock Docs
API reference

Webhooks

Outbound Dock lifecycle webhooks, with endpoints, events, deliveries, and signatures.

Webhooks send an HTTPS POST to your URL when a Dock changes state. Endpoints belong to an organization. Creating and deleting an endpoint need org role admin and a signed-in browser session (Session only); reads need member and accept API keys. Every route takes organizationId. Shared rules are in Conventions.

Event types:

EventSent when
dock.readyA Dock becomes ready.
dock.errorA Dock fails to start.
dock.archivedA Dock stops and is archived.
dock.hydratedAn archived Dock is resumed and ready again.

Each delivery is a JSON body:

{
  "id": "event uuid",
  "type": "dock.ready",
  "occurredAt": "2026-01-01T12:00:00.000Z",
  "dock": { "id": "dock uuid", "state": "ready" },
  "organizationId": "org uuid",
  "workspaceId": "workspace uuid"
}

The dock-signature header is t=<unix seconds>,v1=<hex>, where v1 is the HMAC-SHA256 of <t>.<raw body> keyed with the endpoint's secret. Reject signatures more than 300 seconds old. A 2xx answer marks the delivery sent; 408, 429, 5xx, and network failures are retried with a backoff from 30 seconds doubling to one hour, up to 25 attempts; a 410 disables the endpoint, and disabled endpoints receive nothing; any other 4xx is not retried. Deliveries to one endpoint are limited to 60 per minute, and the receiver has 10 seconds to answer.

Endpoint routes return an endpoint object:

FieldTypeDescription
iduuidEndpoint id.
organizationIduuidOwning organization.
namestringLabel.
urlstringWhere deliveries are sent.
eventsarray of stringsEvent types it receives.
secretPrefixstringFirst 8 characters of the signing secret.
disabledbooleantrue after a receiver answered 410.
createdAttimestampCreation time.
updatedAttimestampLast update.

POST /v1/webhooks/endpoints

Create an endpoint (201). Session only. Role: admin. An organization has at most 10 endpoints, and the URL may not resolve to a private address.

FieldTypeRequiredLimits / defaultDescription
organizationIduuidyesOwning organization.
namestringyes1 to 100Label.
urlstringyeshttps on port 443, max 2000, must not resolve to a private addressWhere deliveries are sent.
eventsarray of stringsyesat least one of the event types aboveEvents to receive.

Response: an endpoint object plus secret, the signing secret, shown only in this response. Errors: validation_error, session_required, organization_not_found, endpoints_exceeded.

GET /v1/webhooks/endpoints

List an organization's endpoints, newest first. Role: member.

FieldTypeRequiredLimits / defaultDescription
organizationId (query)uuidyesOrganization.

Response: an array of endpoint objects. Errors: validation_error, organization_not_found.

GET /v1/webhooks/endpoints/:id

Read one endpoint. Role: member. Takes organizationId in the query as above.

Response: an endpoint object. Errors: validation_error, webhook_endpoint_not_found.

DELETE /v1/webhooks/endpoints/:id

Delete an endpoint. Session only. Role: admin. Takes organizationId in the query as above.

Response: { "removed": true }. Errors: session_required, webhook_endpoint_not_found.

GET /v1/webhooks/endpoints/:id/deliveries

List the endpoint's 100 most recent delivery attempts, newest first. Role: member. Takes organizationId in the query as above.

Response: an array of delivery attempts:

FieldTypeDescription
iduuidAttempt id.
eventIduuidEvent delivered.
endpointIduuidEndpoint it was sent to.
eventstringEvent type.
statusinteger, nullableHTTP status the receiver answered with; null when it did not answer.
errorstring, nullableFailure text.
createdAttimestampWhen the attempt was made.

Errors: validation_error, webhook_endpoint_not_found.

On this page