cURL
curl -X POST https://acme.orgo.space/api/v1/webhook_subscriptions \
-H "Api-Token: $ORGO_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"url": "https://your-app.example.com/webhooks/orgo",
"events": ["user.created", "product_payment.created", "product_payment.updated"],
"secret": "whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9",
"active": true
}'
await fetch("https://acme.orgo.space/api/v1/webhook_subscriptions", {
method: "POST",
headers: {
"Api-Token": process.env.ORGO_API_TOKEN,
"Content-Type": "application/json",
},
body: JSON.stringify({
url: "https://your-app.example.com/webhooks/orgo",
events: ["user.created", "product_payment.created", "product_payment.updated"],
secret: "whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9",
active: true,
}),
});
$client->post('/api/v1/webhook_subscriptions', [
'headers' => ['Api-Token' => getenv('ORGO_API_TOKEN')],
'json' => [
'url' => 'https://your-app.example.com/webhooks/orgo',
'events' => ['user.created', 'product_payment.created', 'product_payment.updated'],
'secret' => 'whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9',
'active' => true,
],
]);
import requests
url = "https://app.orgo.space/api/v1/webhook_subscriptions"
payload = {
"url": "https://your-app.example.com/webhooks/orgo",
"events": ["user.created", "product_payment.created", "product_payment.updated"],
"secret": "whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9",
"active": True,
"description": "Sync new members and payments into our CRM."
}
headers = {
"Api-Token": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.orgo.space/api/v1/webhook_subscriptions"
payload := strings.NewReader("{\n \"url\": \"https://your-app.example.com/webhooks/orgo\",\n \"events\": [\n \"user.created\",\n \"product_payment.created\",\n \"product_payment.updated\"\n ],\n \"secret\": \"whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9\",\n \"active\": true,\n \"description\": \"Sync new members and payments into our CRM.\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Api-Token", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.orgo.space/api/v1/webhook_subscriptions")
.header("Api-Token", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"url\": \"https://your-app.example.com/webhooks/orgo\",\n \"events\": [\n \"user.created\",\n \"product_payment.created\",\n \"product_payment.updated\"\n ],\n \"secret\": \"whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9\",\n \"active\": true,\n \"description\": \"Sync new members and payments into our CRM.\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.orgo.space/api/v1/webhook_subscriptions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Api-Token"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"url\": \"https://your-app.example.com/webhooks/orgo\",\n \"events\": [\n \"user.created\",\n \"product_payment.created\",\n \"product_payment.updated\"\n ],\n \"secret\": \"whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9\",\n \"active\": true,\n \"description\": \"Sync new members and payments into our CRM.\"\n}"
response = http.request(request)
puts response.read_body{
"id": 3,
"url": "https://your-app.example.com/webhooks/orgo",
"events": [
"user.created",
"product_payment.created",
"product_payment.updated"
],
"active": true,
"description": "Sync new members and payments into our CRM.",
"successfulDeliveriesCount": 0,
"failedDeliveriesCount": 0,
"dateCreated": "2026-01-15T10:30:00+00:00"
}WebhookSubscription
Create a webhook subscription
Creates a new webhook subscription or updates an existing one if a subscription with the same URL already exists for the tenant. Accepts url (required), eventTypes, name, secret, isActive, maxRetries, timeoutSeconds, description, headers, and metadata. Validates all fields before persisting. Requires ADMIN_TENANT permission.
POST
/
api
/
v1
/
webhook_subscriptions
cURL
curl -X POST https://acme.orgo.space/api/v1/webhook_subscriptions \
-H "Api-Token: $ORGO_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"url": "https://your-app.example.com/webhooks/orgo",
"events": ["user.created", "product_payment.created", "product_payment.updated"],
"secret": "whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9",
"active": true
}'
await fetch("https://acme.orgo.space/api/v1/webhook_subscriptions", {
method: "POST",
headers: {
"Api-Token": process.env.ORGO_API_TOKEN,
"Content-Type": "application/json",
},
body: JSON.stringify({
url: "https://your-app.example.com/webhooks/orgo",
events: ["user.created", "product_payment.created", "product_payment.updated"],
secret: "whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9",
active: true,
}),
});
$client->post('/api/v1/webhook_subscriptions', [
'headers' => ['Api-Token' => getenv('ORGO_API_TOKEN')],
'json' => [
'url' => 'https://your-app.example.com/webhooks/orgo',
'events' => ['user.created', 'product_payment.created', 'product_payment.updated'],
'secret' => 'whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9',
'active' => true,
],
]);
import requests
url = "https://app.orgo.space/api/v1/webhook_subscriptions"
payload = {
"url": "https://your-app.example.com/webhooks/orgo",
"events": ["user.created", "product_payment.created", "product_payment.updated"],
"secret": "whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9",
"active": True,
"description": "Sync new members and payments into our CRM."
}
headers = {
"Api-Token": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.orgo.space/api/v1/webhook_subscriptions"
payload := strings.NewReader("{\n \"url\": \"https://your-app.example.com/webhooks/orgo\",\n \"events\": [\n \"user.created\",\n \"product_payment.created\",\n \"product_payment.updated\"\n ],\n \"secret\": \"whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9\",\n \"active\": true,\n \"description\": \"Sync new members and payments into our CRM.\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Api-Token", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.orgo.space/api/v1/webhook_subscriptions")
.header("Api-Token", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"url\": \"https://your-app.example.com/webhooks/orgo\",\n \"events\": [\n \"user.created\",\n \"product_payment.created\",\n \"product_payment.updated\"\n ],\n \"secret\": \"whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9\",\n \"active\": true,\n \"description\": \"Sync new members and payments into our CRM.\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.orgo.space/api/v1/webhook_subscriptions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Api-Token"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"url\": \"https://your-app.example.com/webhooks/orgo\",\n \"events\": [\n \"user.created\",\n \"product_payment.created\",\n \"product_payment.updated\"\n ],\n \"secret\": \"whsec_a3f8b2c4d6e8f1a3b5c7d9e1f3a5b7c9\",\n \"active\": true,\n \"description\": \"Sync new members and payments into our CRM.\"\n}"
response = http.request(request)
puts response.read_body{
"id": 3,
"url": "https://your-app.example.com/webhooks/orgo",
"events": [
"user.created",
"product_payment.created",
"product_payment.updated"
],
"active": true,
"description": "Sync new members and payments into our CRM.",
"successfulDeliveriesCount": 0,
"failedDeliveriesCount": 0,
"dateCreated": "2026-01-15T10:30:00+00:00"
}Authorizations
ApiTokenJWT
Server-to-server authentication. Generate a token in the admin UI at
Settings → Developers → API Access. Send the raw token in the
Api-Token header — there is no Bearer prefix.
Tokens can be marked read-only at creation time, in which case the API
rejects any non-GET request with 403 Forbidden.
Body
application/json
The new WebhookSubscription resource
Maximum string length:
255Required range:
0 <= x <= 10Required range:
1 <= x <= 300Response
WebhookSubscription resource created
Maximum string length:
255Required range:
0 <= x <= 10Required range:
1 <= x <= 300Example:
"/api/v1/tenants/1"

