> ## Documentation Index
> Fetch the complete documentation index at: https://docs.reply.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a webhook subscription

> <small>_Requires the `webhooks:write` scope (or a broader one that includes it)._</small>

Creates a new webhook subscription for the authenticated user.

`scope` defaults to `personal` when omitted. `team`-scope subscriptions are accepted
only when policy allows: any member may create them for public teams or organization
mode; only the team owner may create them for private teams.

Attempting to create an `organization`-scope subscription is rejected with
`code: webHook.organizationScopeNotImplemented` — the value is reserved for future use.



## OpenAPI

````yaml /api-reference/bundled.yaml post /v3/webhooks
openapi: 3.1.0
info:
  version: 3.0.0
  title: Reply API
  description: API for managing email sequences, contacts, and automation workflows
servers:
  - url: https://api.reply.io
security:
  - bearerAuth: []
tags:
  - name: User Account
    description: Account information and authentication verification
  - name: Accounts
    description: Manage accounts (companies/organizations)
  - name: AI SDR Insights
    description: Read AI SDR insights for sequence contacts
  - name: AI SDR Intent Signals
    description: >-
      Read Reply industry IDs and technology slugs used in AI SDR intent-signal
      configuration (typeahead)
  - name: AI SDR Sequences
    description: >-
      Manage AI SDR sequences and their AI SDR-specific settings — create, read
      settings, partial update, autopilot enable/disable/force-start, approval
      mode, generated step types, and playbook/knowledge-base connections
  - name: AI SDR Web Search
    description: Find contacts via AI-driven web search and review past searches
  - name: Attachments
    description: >-
      Upload file attachments used across email templates, sequence steps, and
      direct emails
  - name: Account Lists
    description: Manage account lists and account membership
  - name: Background Jobs
    description: >-
      Track and cancel asynchronous background operations (e.g., email
      validation)
  - name: Custom Fields
    description: Manage custom contact fields
  - name: Direct Outreach
    description: >-
      Send one-off outreach directly to a contact outside of any sequence —
      direct emails and LinkedIn connection requests, messages, InMails, and
      voice messages
  - name: Contact Blacklist Rules
    description: Manage blacklist rules for domains, emails, and email exceptions
  - name: Contact Enrichment
    description: >-
      Enrich contacts with emails, phone numbers, LinkedIn data, and AI-filled
      custom fields
  - name: Contact Lists
    description: Manage contact lists and contact membership
  - name: Contacts
    description: Manage individual contacts
  - name: Email Accounts
    description: Manage email accounts used for sending and receiving
  - name: Email Templates
    description: Manage email templates and template folders
  - name: Email Validations
    description: Estimate and schedule asynchronous email validation jobs
  - name: Holiday Calendars
    description: Manage holiday calendars for scheduling
  - name: Inbox
    description: >-
      Manage inbox threads and per-team thread categories — list/filter, read
      state, replies, category assignment, and meeting-intent flagging
  - name: LinkedIn Accounts
    description: Manage LinkedIn accounts for outreach
  - name: Live Data
    description: >-
      Find new contacts via Live Data searches and read typeahead values for the
      Live Data / Autopilot filter sidebar
  - name: AI SDR Knowledge Bases
    description: >-
      Manage AI SDR knowledge bases — collections of documents, links, reply
      handlers, and reengagement cards that inform the agent's responses
  - name: AI SDR Offers
    description: >-
      Manage AI SDR offers — bundles of company-context inputs (ICP, pain
      points, value propositions, etc.) used to personalize outreach
  - name: AI SDR Pending Approvals
    description: >-
      Review, send, regenerate, and provide feedback on AI-generated messages
      awaiting human approval
  - name: AI SDR Playbooks
    description: >-
      Manage AI SDR playbooks — tone, voice, and style guides applied during
      personalized message generation
  - name: Reports
    description: >-
      Generate and access performance reports across email, calls, tasks,
      LinkedIn, and team performance
  - name: Schedules
    description: Manage email send schedules and timing
  - name: Settings
    description: Manage team and user settings
  - name: Sequence Contacts
    description: Manage contacts within sequences
  - name: Sequence Email Accounts
    description: Manage email accounts linked to sequences
  - name: Sequence Folders
    description: Organize sequences into folders
  - name: Sequence LinkedIn Accounts
    description: Manage LinkedIn accounts linked to sequences
  - name: AI SDR Sequence Preview
    description: >-
      Read and regenerate per-contact previews of the messages a sequence will
      send, and provide feedback on preview messages
  - name: Sequence Steps
    description: Manage individual steps in sequences
  - name: Sequence Templates
    description: Manage sequence templates
  - name: Sequences
    description: Manage email automation sequences
  - name: AI SDR Strategist
    description: Trigger AI Strategist runs
  - name: Tasks
    description: Manage tasks and to-do items
  - name: Webhooks
    description: Manage webhook subscriptions and inspect delivery history
paths:
  /v3/webhooks:
    post:
      tags:
        - Webhooks
      summary: Create a webhook subscription
      description: >-
        <small>_Requires the `webhooks:write` scope (or a broader one that
        includes it)._</small>


        Creates a new webhook subscription for the authenticated user.


        `scope` defaults to `personal` when omitted. `team`-scope subscriptions
        are accepted

        only when policy allows: any member may create them for public teams or
        organization

        mode; only the team owner may create them for private teams.


        Attempting to create an `organization`-scope subscription is rejected
        with

        `code: webHook.organizationScopeNotImplemented` — the value is reserved
        for future use.
      operationId: CreateWebhook
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              title: WebHookCreationRequest
              description: Request body for creating a webhook subscription.
              properties:
                eventType:
                  type: string
                  description: >-
                    Event type this subscription should fire on. Must be one of
                    the values returned by

                    `GET /v3/webhooks/events`.
                  example: email_replied
                url:
                  type: string
                  format: uri
                  maxLength: 1024
                  description: >-
                    Absolute `http`/`https` URL that will receive the webhook
                    payload.
                  example: https://example.com/hooks/reply
                scope:
                  type: string
                  title: WebHookScope
                  description: >-
                    Scope that determines which users' activity triggers the
                    webhook.


                    - `personal` — fires only for activity of the subscription
                    owner.

                    - `team` — fires for activity of any member of the owner's
                    team. Creation requires the current user to be the team
                    owner for private teams; anyone can create for public teams.

                    - `organization` — reserved for future use. The API
                    currently rejects creation/update with this value
                    (`errorCode: 5`).
                  enum:
                    - personal
                    - team
                    - organization
                  example: personal
                enabled:
                  type: boolean
                  description: >-
                    Create the subscription in an enabled (firing) state.
                    Defaults to `true`. After

                    creation, toggle the state via the dedicated

                    `POST /v3/webhooks/{id}/enable` and `POST
                    /v3/webhooks/{id}/disable` endpoints.
                  default: true
                payloadConfig:
                  type: object
                  title: WebHookPayloadConfig
                  description: >-
                    Optional flags that enrich the delivered webhook payload
                    with extra fields from the originating email/contact.
                  properties:
                    includeEmailUrl:
                      type: boolean
                      description: >-
                        Include a link to the tracked email in the delivered
                        payload.
                    includeEmailText:
                      type: boolean
                      description: >-
                        Include the plain-text body of the email in the
                        delivered payload.
                    includeProspectCustomFields:
                      type: boolean
                      description: >-
                        Include the contact's custom-field values in the
                        delivered payload.
                  example:
                    includeEmailUrl: true
                    includeEmailText: false
                    includeProspectCustomFields: true
              required:
                - eventType
                - url
              example:
                eventType: email_replied
                url: https://example.com/hooks/reply
                scope: personal
                enabled: true
                payloadConfig:
                  includeEmailUrl: true
                  includeEmailText: false
                  includeProspectCustomFields: true
      responses:
        '201':
          description: Webhook subscription created successfully.
          content:
            application/json:
              schema:
                type: object
                title: WebHook
                description: >-
                  A webhook subscription. The subscription fires a single event
                  type to a configured URL

                  when activity matching the subscription's `scope` occurs.
                properties:
                  id:
                    type: integer
                    readOnly: true
                    description: Unique identifier for the webhook subscription.
                  eventType:
                    type: string
                    description: >-
                      Event type this subscription fires on. One of the values
                      returned by

                      `GET /v3/webhooks/events`.
                    example: email_replied
                  url:
                    type: string
                    format: uri
                    description: >-
                      Absolute `http`/`https` URL that receives the webhook
                      payload.
                    example: https://example.com/hooks/reply
                  scope:
                    type: string
                    title: WebHookScope
                    description: >-
                      Scope that determines which users' activity triggers the
                      webhook.


                      - `personal` — fires only for activity of the subscription
                      owner.

                      - `team` — fires for activity of any member of the owner's
                      team. Creation requires the current user to be the team
                      owner for private teams; anyone can create for public
                      teams.

                      - `organization` — reserved for future use. The API
                      currently rejects creation/update with this value
                      (`errorCode: 5`).
                    enum:
                      - personal
                      - team
                      - organization
                    example: personal
                  enabled:
                    type: boolean
                    description: >-
                      If `false`, the subscription does not fire. Toggle via the
                      dedicated

                      `POST /v3/webhooks/{id}/enable` and `POST
                      /v3/webhooks/{id}/disable`

                      endpoints — the state cannot be changed through `PUT`.
                  createdAt:
                    type: string
                    format: date-time
                    readOnly: true
                    description: >-
                      ISO-8601 timestamp (UTC) when the subscription was
                      created.
                  payloadConfig:
                    type: object
                    title: WebHookPayloadConfig
                    description: >-
                      Optional flags that enrich the delivered webhook payload
                      with extra fields from the originating email/contact.
                    properties:
                      includeEmailUrl:
                        type: boolean
                        description: >-
                          Include a link to the tracked email in the delivered
                          payload.
                      includeEmailText:
                        type: boolean
                        description: >-
                          Include the plain-text body of the email in the
                          delivered payload.
                      includeProspectCustomFields:
                        type: boolean
                        description: >-
                          Include the contact's custom-field values in the
                          delivered payload.
                    example:
                      includeEmailUrl: true
                      includeEmailText: false
                      includeProspectCustomFields: true
                example:
                  id: 1823
                  eventType: email_replied
                  url: https://example.com/hooks/reply
                  scope: personal
                  enabled: true
                  createdAt: '2026-04-17T12:00:00+00:00'
                  payloadConfig:
                    includeEmailUrl: true
                    includeEmailText: false
                    includeProspectCustomFields: true
        '400':
          description: >-
            Request-body validation failed, or a domain rule rejected the create
            (unknown

            event, invalid URL, invalid scope value, or organization scope
            reserved for

            future use).
          content:
            application/problem+json:
              schema:
                oneOf:
                  - allOf:
                      - allOf:
                          - type: object
                            title: Problem Details
                            description: >-
                              Bare RFC 9457 problem-details envelope. Returned
                              by middleware-level errors

                              that don't carry domain context: 401 Unauthorized
                              (auth middleware),

                              429 Too Many Requests (rate-limit middleware), and
                              route-level 404 / 405 /

                              415 (framework middleware).


                              Business and validation responses extend this
                              envelope and add additional

                              fields — see `business-problem.model.yaml` (adds
                              `code` slug) and

                              `validation-problem.model.yaml` (adds `errors[]`
                              array).
                            properties:
                              title:
                                type: string
                                description: Short, human-readable summary of the problem.
                              status:
                                type: integer
                                description: HTTP status code.
                                minimum: 100
                                maximum: 599
                              detail:
                                type: string
                                description: >-
                                  Human-readable explanation specific to this
                                  occurrence.
                          - type: object
                            properties:
                              errors:
                                type: array
                                description: >-
                                  List of field-level validation errors. Always
                                  non-empty when this

                                  envelope is returned. Each entry pins a single
                                  offending field

                                  via JSON Pointer plus a sanitized detail
                                  string.
                                items:
                                  type: object
                                  title: Validation Error
                                  description: A single field-level validation error.
                                  properties:
                                    pointer:
                                      type: string
                                      description: >-
                                        JSON Pointer (RFC 6901) to the offending
                                        field — e.g.

                                        `/steps/0/subject`.


                                        * An empty string (`""`) means the error
                                        applies to the whole
                                          request body (e.g. body is missing or unparseable).
                                        * For route or query parameter failures
                                        the pointer is the parameter
                                          name (e.g. `id`, `top`).
                                      example: /steps/0/subject
                                    detail:
                                      type: string
                                      description: >-
                                        Sanitized, human-readable explanation of
                                        this field's error. One of a

                                        small set of templates — `"Field is
                                        required."`, `"Value has an

                                        invalid type."`, `"Value has an invalid
                                        format."`, `"Request body is

                                        not valid JSON."`, `"The request body is
                                        required and cannot be

                                        empty."` — or a FluentValidator message
                                        on body endpoints.
                                      example: Field is required.
                        title: Validation Problem
                        description: >-
                          Input-validation error response at 400. Returned when
                          the request body

                          fails binding, FluentValidator rules, or when
                          route/query parameter

                          attribute validation (`[Range]`, `[Required]`) fails.
                          Route, query, and

                          body errors are combined into a single `errors[]`
                          array — clients should

                          not assume one error per request.
                      - example:
                          title: Validation failed
                          status: 400
                          detail: The request body contains validation errors.
                          errors:
                            - pointer: /name
                              detail: Field is required.
                  - allOf:
                      - allOf:
                          - type: object
                            title: Problem Details
                            description: >-
                              Bare RFC 9457 problem-details envelope. Returned
                              by middleware-level errors

                              that don't carry domain context: 401 Unauthorized
                              (auth middleware),

                              429 Too Many Requests (rate-limit middleware), and
                              route-level 404 / 405 /

                              415 (framework middleware).


                              Business and validation responses extend this
                              envelope and add additional

                              fields — see `business-problem.model.yaml` (adds
                              `code` slug) and

                              `validation-problem.model.yaml` (adds `errors[]`
                              array).
                            properties:
                              title:
                                type: string
                                description: Short, human-readable summary of the problem.
                              status:
                                type: integer
                                description: HTTP status code.
                                minimum: 100
                                maximum: 599
                              detail:
                                type: string
                                description: >-
                                  Human-readable explanation specific to this
                                  occurrence.
                          - type: object
                            properties:
                              code:
                                type: string
                                description: >-
                                  Stable, machine-readable error slug in the
                                  form

                                  `"<resource>.<variant>"`.


                                  * `resource` is the camelCased domain — e.g.
                                  `sequence`,
                                    `contact`, `inboxThread`, `blacklistDomainRule`.
                                  * `variant` is the camelCased specific failure
                                  mode — e.g.
                                    `notFound`, `forbidden`, `duplicateName`, `globalRuleReadOnly`.

                                  Use `code` for programmatic error handling;
                                  use `detail` for

                                  user-facing messages. Slugs are stable across
                                  server-side enum

                                  reorderings and never change meaning under a
                                  given resource.
                                pattern: ^[a-z][a-zA-Z0-9]*(\.[a-z][a-zA-Z0-9]*)+$
                                example: sequence.notFound
                        title: Business Problem
                        description: >-
                          Domain error response carrying a stable, namespaced
                          error slug.

                          Emitted for most 4xx responses (business 400, 403,
                          404, 409, …) and

                          for 503 when a downstream dependency is unavailable.
                      - example:
                          title: Bad Request
                          status: 400
                          detail: Pagination parameters are invalid.
                          code: sequence.invalidPagination
              examples:
                validation_failed:
                  summary: Body validation failure (FluentValidator)
                  value:
                    title: Validation failed
                    status: 400
                    detail: The request body contains validation errors.
                    errors:
                      - pointer: /url
                        detail: '''url'' must not be empty.'
                invalid_event:
                  summary: Unknown event type
                  value:
                    title: Bad Request
                    status: 400
                    detail: Unknown webhook event 'email_clicked'.
                    code: webHook.invalidEvent
                invalid_url:
                  summary: Malformed URL
                  value:
                    title: Bad Request
                    status: 400
                    detail: Url must be a valid absolute http(s) URL.
                    code: webHook.invalidUrl
                invalid_scope:
                  summary: Invalid scope value
                  value:
                    title: Bad Request
                    status: 400
                    detail: Unknown webhook scope value.
                    code: webHook.invalidScope
                organization_scope_not_implemented:
                  summary: Organization scope reserved
                  value:
                    title: Bad Request
                    status: 400
                    detail: Organization-scope webhooks are not yet implemented.
                    code: webHook.organizationScopeNotImplemented
        '401':
          description: >-
            Unauthorized. The response body is empty; check the
            `WWW-Authenticate` header for the expected scheme.
          content:
            application/problem+json:
              schema:
                allOf:
                  - type: object
                    title: Problem Details
                    description: >-
                      Bare RFC 9457 problem-details envelope. Returned by
                      middleware-level errors

                      that don't carry domain context: 401 Unauthorized (auth
                      middleware),

                      429 Too Many Requests (rate-limit middleware), and
                      route-level 404 / 405 /

                      415 (framework middleware).


                      Business and validation responses extend this envelope and
                      add additional

                      fields — see `business-problem.model.yaml` (adds `code`
                      slug) and

                      `validation-problem.model.yaml` (adds `errors[]` array).
                    properties:
                      title:
                        type: string
                        description: Short, human-readable summary of the problem.
                      status:
                        type: integer
                        description: HTTP status code.
                        minimum: 100
                        maximum: 599
                      detail:
                        type: string
                        description: >-
                          Human-readable explanation specific to this
                          occurrence.
                  - example:
                      title: Unauthorized
                      status: 401
                      detail: Authentication credentials are missing or invalid.
        '403':
          description: >-
            The caller is not allowed to create a `team`-scope subscription for
            their team

            (private team, caller is not the owner).
          content:
            application/problem+json:
              schema:
                allOf:
                  - allOf:
                      - type: object
                        title: Problem Details
                        description: >-
                          Bare RFC 9457 problem-details envelope. Returned by
                          middleware-level errors

                          that don't carry domain context: 401 Unauthorized
                          (auth middleware),

                          429 Too Many Requests (rate-limit middleware), and
                          route-level 404 / 405 /

                          415 (framework middleware).


                          Business and validation responses extend this envelope
                          and add additional

                          fields — see `business-problem.model.yaml` (adds
                          `code` slug) and

                          `validation-problem.model.yaml` (adds `errors[]`
                          array).
                        properties:
                          title:
                            type: string
                            description: Short, human-readable summary of the problem.
                          status:
                            type: integer
                            description: HTTP status code.
                            minimum: 100
                            maximum: 599
                          detail:
                            type: string
                            description: >-
                              Human-readable explanation specific to this
                              occurrence.
                      - type: object
                        properties:
                          code:
                            type: string
                            description: >-
                              Stable, machine-readable error slug in the form

                              `"<resource>.<variant>"`.


                              * `resource` is the camelCased domain — e.g.
                              `sequence`,
                                `contact`, `inboxThread`, `blacklistDomainRule`.
                              * `variant` is the camelCased specific failure
                              mode — e.g.
                                `notFound`, `forbidden`, `duplicateName`, `globalRuleReadOnly`.

                              Use `code` for programmatic error handling; use
                              `detail` for

                              user-facing messages. Slugs are stable across
                              server-side enum

                              reorderings and never change meaning under a given
                              resource.
                            pattern: ^[a-z][a-zA-Z0-9]*(\.[a-z][a-zA-Z0-9]*)+$
                            example: sequence.notFound
                    title: Business Problem
                    description: >-
                      Domain error response carrying a stable, namespaced error
                      slug.

                      Emitted for most 4xx responses (business 400, 403, 404,
                      409, …) and

                      for 503 when a downstream dependency is unavailable.
                  - example:
                      title: Forbidden
                      status: 403
                      detail: You do not have permission to access this resource.
                      code: sequence.forbidden
              example:
                title: Forbidden
                status: 403
                detail: >-
                  Team-scope webhook subscriptions are not allowed for your
                  current team configuration.
                code: webHook.teamScopeForbidden
        '409':
          description: The active webhook-subscription limit for the user has been reached.
          content:
            application/problem+json:
              schema:
                allOf:
                  - allOf:
                      - type: object
                        title: Problem Details
                        description: >-
                          Bare RFC 9457 problem-details envelope. Returned by
                          middleware-level errors

                          that don't carry domain context: 401 Unauthorized
                          (auth middleware),

                          429 Too Many Requests (rate-limit middleware), and
                          route-level 404 / 405 /

                          415 (framework middleware).


                          Business and validation responses extend this envelope
                          and add additional

                          fields — see `business-problem.model.yaml` (adds
                          `code` slug) and

                          `validation-problem.model.yaml` (adds `errors[]`
                          array).
                        properties:
                          title:
                            type: string
                            description: Short, human-readable summary of the problem.
                          status:
                            type: integer
                            description: HTTP status code.
                            minimum: 100
                            maximum: 599
                          detail:
                            type: string
                            description: >-
                              Human-readable explanation specific to this
                              occurrence.
                      - type: object
                        properties:
                          code:
                            type: string
                            description: >-
                              Stable, machine-readable error slug in the form

                              `"<resource>.<variant>"`.


                              * `resource` is the camelCased domain — e.g.
                              `sequence`,
                                `contact`, `inboxThread`, `blacklistDomainRule`.
                              * `variant` is the camelCased specific failure
                              mode — e.g.
                                `notFound`, `forbidden`, `duplicateName`, `globalRuleReadOnly`.

                              Use `code` for programmatic error handling; use
                              `detail` for

                              user-facing messages. Slugs are stable across
                              server-side enum

                              reorderings and never change meaning under a given
                              resource.
                            pattern: ^[a-z][a-zA-Z0-9]*(\.[a-z][a-zA-Z0-9]*)+$
                            example: sequence.notFound
                    title: Business Problem
                    description: >-
                      Domain error response carrying a stable, namespaced error
                      slug.

                      Emitted for most 4xx responses (business 400, 403, 404,
                      409, …) and

                      for 503 when a downstream dependency is unavailable.
                  - example:
                      title: Conflict
                      status: 409
                      detail: A resource with this name already exists.
                      code: sequence.duplicateName
              example:
                title: Conflict
                status: 409
                detail: Limit of active webhook subscriptions reached (50).
                code: webHook.limitReached
        '429':
          description: Too Many Requests
          headers:
            Retry-After:
              description: Seconds to wait before retrying
              schema:
                type: integer
                minimum: 1
          content:
            application/problem+json:
              schema:
                allOf:
                  - type: object
                    title: Problem Details
                    description: >-
                      Bare RFC 9457 problem-details envelope. Returned by
                      middleware-level errors

                      that don't carry domain context: 401 Unauthorized (auth
                      middleware),

                      429 Too Many Requests (rate-limit middleware), and
                      route-level 404 / 405 /

                      415 (framework middleware).


                      Business and validation responses extend this envelope and
                      add additional

                      fields — see `business-problem.model.yaml` (adds `code`
                      slug) and

                      `validation-problem.model.yaml` (adds `errors[]` array).
                    properties:
                      title:
                        type: string
                        description: Short, human-readable summary of the problem.
                      status:
                        type: integer
                        description: HTTP status code.
                        minimum: 100
                        maximum: 599
                      detail:
                        type: string
                        description: >-
                          Human-readable explanation specific to this
                          occurrence.
              example:
                title: Too Many Requests
                status: 429
                detail: Rate limit exceeded. Retry after 60 seconds.
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Authenticate every request with a Bearer token. Pass your Reply API key
        in the

        `Authorization` header:


        ```

        Authorization: Bearer <your-api-key>

        ```


        Get your API key from the Reply dashboard: **Settings → API Key**.

````