> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dacard.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Webhook

> Register a new outbound webhook endpoint. The response includes the
signing secret; this is the only time the secret is returned in plain
text. Store it securely and use it to verify webhook signatures.

Allowed events: `score.completed`, `subscription.changed`.

**Permission:** `account:manage_integrations` (admin+ role)




## OpenAPI

````yaml post /api/webhooks
openapi: 3.1.0
info:
  title: Dacard.ai API
  description: >
    Decision intelligence platform for AI-native product teams.

    Score, connect, and compound your product maturity across two original
    frameworks.
  version: 0.1.0
  contact:
    name: Darren Card
    email: darren@darrencard.com
    url: https://darrencard.com
  license:
    name: Proprietary
servers:
  - url: https://app.dacard.ai
    description: Production
  - url: http://localhost:3001
    description: Local development
security: []
tags:
  - name: Scoring
    description: AI maturity scoring engine
  - name: Lifecycle
    description: Development Lifecycle assessment
  - name: Products
    description: Product management and analytics
  - name: Dashboard
    description: Dashboard and suite analytics
  - name: Account
    description: Account and team management
  - name: Billing
    description: Stripe billing integration
  - name: User
    description: User profile, onboarding, and preferences
  - name: System
    description: Health checks and diagnostics
  - name: Internal
    description: Internal and admin endpoints (PQL tracking, demo data management)
  - name: Agents
    description: Agent Studio - autonomous AI agents, triggers, and artifacts
  - name: Intelligence
    description: Alerts, coaching context, and score timeline
  - name: Anomalies
    description: Signal anomaly detection, acknowledgment, and sensitivity overrides
  - name: Outcomes
    description: Longitudinal outcome observations for validation study (E2.2)
  - name: Settings
    description: User and account notification preferences
  - name: Webhooks
    description: Outbound webhook management
  - name: API Keys
    description: API key management (Team and Enterprise plans)
paths:
  /api/webhooks:
    post:
      tags:
        - Webhooks
      summary: Create a webhook
      description: |
        Register a new outbound webhook endpoint. The response includes the
        signing secret; this is the only time the secret is returned in plain
        text. Store it securely and use it to verify webhook signatures.

        Allowed events: `score.completed`, `subscription.changed`.

        **Permission:** `account:manage_integrations` (admin+ role)
      operationId: createWebhook
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WebhookCreate'
      responses:
        '201':
          description: Webhook created (secret included in this response only)
          content:
            application/json:
              schema:
                type: object
                properties:
                  webhook:
                    $ref: '#/components/schemas/WebhookWithSecret'
        '400':
          description: Invalid URL or no valid events
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          description: Insufficient permissions
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - clerkAuth: []
        - bearerAuth: []
components:
  schemas:
    WebhookCreate:
      type: object
      required:
        - url
      properties:
        url:
          type: string
          format: uri
          description: Destination URL (must be HTTPS)
          example: https://example.com/hooks/dacard
        events:
          type: array
          items:
            type: string
            enum:
              - score.completed
              - subscription.changed
          description: Events to subscribe to. Defaults to ["score.completed"] if omitted.
          default:
            - score.completed
    WebhookWithSecret:
      allOf:
        - $ref: '#/components/schemas/Webhook'
        - type: object
          properties:
            secret:
              type: string
              writeOnly: true
              description: >-
                HMAC-SHA256 signing secret (hex-encoded, 64 chars). Only
                returned on creation.
              example: a3f9b2...
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: string
          description: Machine-readable error message
        code:
          type: string
          description: Error code
          enum:
            - AUTH_REQUIRED
            - FORBIDDEN
            - NOT_FOUND
            - INVALID_URL
            - CRAWL_FAILED
            - SCORE_FAILED
            - QUOTA_EXCEEDED
            - ANON_RATE_LIMIT
            - SIGNAL_RATE_LIMITED
            - SIGNAL_VALIDATION_FAILED
            - SERVER_ERROR
        message:
          type: string
          description: Human-readable message
        details:
          description: Additional context
    Webhook:
      type: object
      properties:
        id:
          type: string
          format: uuid
        accountId:
          type: string
          format: uuid
        url:
          type: string
          format: uri
          description: Destination URL for webhook deliveries
        events:
          type: array
          items:
            type: string
            enum:
              - score.completed
              - subscription.changed
          description: Events this webhook subscribes to
        enabled:
          type: boolean
          default: true
        createdAt:
          type: string
          format: date-time
  responses:
    Unauthorized:
      description: Authentication required
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: Authentication required
            code: AUTH_REQUIRED
  securitySchemes:
    clerkAuth:
      type: apiKey
      in: cookie
      name: __session
      description: |
        Clerk session cookie. Authentication is handled by Clerk.
        Sign in at https://app.dacard.ai/sign-in to obtain a session.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: |
        Clerk JWT session token. Obtain via Clerk's frontend SDK
        using `getToken()` or via the Clerk Backend API.

````