☰ Menu · Webhook endpoints
API reference

Webhook endpoints

Where we send events for this venue.

POST/v1/webhook_endpoints
Scope: webhooks:write

Adds an endpoint. url must be public HTTPS. events is a list of event types; leave it out to receive all. The secret for signatures is in this response only.

curl
curl https://loyaltyfy.io/api/v1/webhook_endpoints \
  -H "Authorization: Bearer sk_test_..." \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://pos.example.com/loyaltyfy/webhooks",
    "events": ["transaction.completed", "order.created"]
  }'
Response · 201
{
  "object": "webhook_endpoint",
  "id": "01c2a784-4bcf-43b9-8ac9-ddbad7a25341",
  "url": "https://pos.example.com/loyaltyfy/webhooks",
  "description": null,
  "events": ["transaction.completed", "order.created"],
  "status": "enabled",
  "disabled_reason": null,
  "livemode": false,
  "created_at": "2026-10-06T18:17:32.381+00:00",
  "secret": "whsec_UvjHvXfPk80ITYl_xPeAtskI0WjR8-PS"
}
GET/v1/webhook_endpoints
Scope: webhooks:write

All endpoints of the venue.

GET/v1/webhook_endpoints/{id}
Scope: webhooks:write

One endpoint, with its status and the reason if it was disabled.

PATCH/v1/webhook_endpoints/{id}
Scope: webhooks:write

Changes url, events, description, or enabled. Use enabled: true to turn an endpoint back on after it was disabled for failures.

DELETE/v1/webhook_endpoints/{id}
Scope: webhooks:write

Removes the endpoint. Deliveries in progress stop.

POST/v1/webhook_endpoints/{id}/test
Scope: webhooks:write

Sends a signed test.ping event now and tells you what your endpoint answered.

curl
curl -X POST https://loyaltyfy.io/api/v1/webhook_endpoints/01c2a784-4bcf-43b9-8ac9-ddbad7a25341/test \
  -H "Authorization: Bearer sk_test_..."

# { "object": "webhook_test", "delivered": true, "status_code": 200, "error": null }
Questions about an integration: api@loyaltyfy.io. We answer within one business day.