Skip to main content
import { createClient } from "@mailsai/sdk";

const client = createClient(); // reads MAILS_API_KEY

const result = await client.webhooks.update(
  "whe_01JZX8K3M9Q4P7VN2YB6RTDC0E",
  {
    active: false,
  },
);
console.log(result);
{
  "id": "whe_01JZX8K3M9Q4P7VN2YB6RTDC0E",
  "url": "https://example.com",
  "event_types": ["<event_types>"],
  "description": "<description>",
  "active": false,
  "secret_rotated_at": "2026-10-04T12:00:00.000Z",
  "previous_secret_expires_at": "2026-10-04T12:00:00.000Z",
  "created_at": "<created_at>"
}

Update a webhook endpoint

Changes an endpoint's URL, event types, description or active state.
PATCH/v1/webhooks/{id}scope · manage
import { createClient } from "@mailsai/sdk";

const client = createClient(); // reads MAILS_API_KEY

const result = await client.webhooks.update(
  "whe_01JZX8K3M9Q4P7VN2YB6RTDC0E",
  {
    active: false,
  },
);
console.log(result);
{
  "id": "whe_01JZX8K3M9Q4P7VN2YB6RTDC0E",
  "url": "https://example.com",
  "event_types": ["<event_types>"],
  "description": "<description>",
  "active": false,
  "secret_rotated_at": "2026-10-04T12:00:00.000Z",
  "previous_secret_expires_at": "2026-10-04T12:00:00.000Z",
  "created_at": "<created_at>"
}

Path Parameters

idstringrequired

Webhook endpoint id (whe_…).

Body Parameters

urlstring

A new https:// URL for the endpoint, checked as on create. The signing secret stays the same, and retries still due go to the new URL; left out, the URL is unchanged.

event_typesstring[]

Events to deliver, at least one. "*" is every event except thread.created, thread.updated, thread.deleted and message.delayed, sent only to an endpoint that names them.

descriptionstring

Replaces the endpoint's note, up to 255 characters; left out, it is unchanged. null is refused: clear it with an empty string, which is returned as it is.

activeboolean

false pauses the endpoint: nothing is delivered to it, events raised meanwhile are not sent when it resumes, and a retry that comes due is dead-lettered. true resumes it; left out, it is unchanged.

An empty event_types list is refused with 422 invalid_param_value, as on create. An app connected by sign-in may change everything except url (403 connected_app_not_allowed).

Response

idstring

Webhook endpoint id (whe_…).

urlstring

The URL events are POSTed to.

event_typesstring[]

The event types this endpoint receives. * is every type except thread.created, thread.updated, thread.deleted and message.delayed, which reach an endpoint only when it lists them by name.

descriptionstring | null

Your note about the endpoint, or null when it has none.

activeboolean

false while the endpoint is paused: nothing is delivered to it until PATCH /v1/webhooks/{id} sets it back to true.

secret_rotated_atstring | null

When the signing secret was last rotated.

previous_secret_expires_atstring | null

While set, deliveries are signed with both the new and the previous secret; null once the previous one stops signing.

created_atstring

When the endpoint was created (ISO 8601, UTC).

Was this page helpful?