Enable or disable a webhook destination
View .mdPATCH /v1/developer/webhook-subscriptions/{subscriptionId}
Operation ID: updateDeveloperWebhookSubscription
Changes enabled only; URL, scope, event types and envelope version remain fixed. Disabling requires webhooks.write. Enabling additionally requires events.read, webhooks.read and every selected event-family grant. Create a replacement destination to change its contract. Server credentials only. Application, installation, collection, and TEST/LIVE scope are resolved from the credential. Legacy collection webhook destinations are separate. TEST and LIVE events are isolated; neither event grants charging, booking or marketing authority.
Contract status
Section titled “Contract status”| Field | Value |
|---|---|
| Maturity | beta |
| Required capability | webhooks.write |
| Freshness class | authenticated-state |
| Quota cost | 1 |
All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential’s installation grants; identifiers in the URL never grant access.
Request parameters
Section titled “Request parameters”| Name | In | Type | Required | Description |
|---|---|---|---|---|
subscriptionId |
path | string | yes |
Request body
Section titled “Request body”The request body is JSON. The canonical schema is:
{ "type": "object", "additionalProperties": false, "required": [ "enabled" ], "properties": { "enabled": { "type": "boolean" } }}Minimal example:
{ "enabled": true}Set KISMET_API_ORIGIN=https://api.ksmt.app and configure KISMET_DEVELOPER_API_KEY in your environment. Run server-credential requests from your backend, not browser code.
curl --request PATCH \ "$KISMET_API_ORIGIN/v1/developer/webhook-subscriptions/{subscriptionId}" \ --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \ --header "Accept: application/json" \ --header "Content-Type: application/json" \ --data '{"enabled":true}'Responses
Section titled “Responses”| Status | Meaning |
|---|---|
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 404 | The authorized resource was not found. |
| 409 | Request conflicts with the installation environment or current state. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |
200 response example
Section titled “200 response example”{ "id": "77777777-7777-4777-8777-777777777777", "name": "Application events", "url": "https://builder.example/webhooks/kismet", "eventTypes": [ "payment_method.added" ], "enabled": false, "envelopeVersion": "2", "applicationId": "22222222-2222-4222-8222-222222222222", "installationId": "33333333-3333-4333-8333-333333333333", "collectionId": "44444444-4444-4444-8444-444444444444", "environment": "TEST", "secretHint": "abcd", "createdAt": "2026-09-23T12:00:01.000Z"}200 response schema
Section titled “200 response schema”Content type: application/json. Required fields, nullable values, and nested structures are defined below.
View complete response schema
{ "type": "object", "properties": { "id": { "type": "string", "format": "uuid" }, "name": { "type": "string" }, "url": { "type": "string", "format": "uri" }, "eventTypes": { "type": "array", "items": { "type": "string" } }, "enabled": { "type": "boolean" }, "envelopeVersion": { "type": "string", "enum": [ "2" ] }, "applicationId": { "type": "string", "format": "uuid" }, "installationId": { "type": "string", "format": "uuid" }, "collectionId": { "type": "string", "format": "uuid" }, "environment": { "type": "string", "enum": [ "TEST", "LIVE" ] }, "secretHint": { "type": "string", "nullable": true }, "createdAt": { "type": "string", "format": "date-time" } }, "required": [ "id", "name", "url", "eventTypes", "enabled", "envelopeVersion", "applicationId", "installationId", "collectionId", "environment", "secretHint", "createdAt" ], "additionalProperties": false}