Skip to content
POSTAPI key

Register an endpoint

POSTapi.trackingmcp.com/v1/webhooks

Register an HTTPS URL to receive signed event deliveries. The signing secret is returned once here and never again: store it before you close the connection. An unrecognised event type is dropped silently rather than rejected, so read event_types back from the response. Answers 201 on success, 400 INVALID_URL when the URL is missing or not https.

Request body

urlstringrequired

Where we post deliveries. Must start with https://.

event_typesstring[]

Event types to receive. Omit or send [] to receive every event type we emit.

descriptionstring

Your own label. We never interpret it.

Response fields

Derived from the example response.

okboolean

Whether the request succeeded.

dataobject

The payload. Everything an endpoint returns sits under this key.

data.idstring

Stable identifier for the record. On the tracking endpoints this is the container UUID, except on a portfolio summary row, where it is the container number.

data.urlstring
data.event_typesstring[]
data.descriptionstring

The carrier own phrasing for the event, falling back to our word for the code.

data.activeboolean
data.created_atstring

When the record was created (ISO 8601).

data.secretstring
curl -X POST 'https://api.trackingmcp.com/v1/webhooks' \
  -H "Authorization: Bearer tmcp_YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://hooks.example.com/trackingmcp","event_types":["api_change_announced"],"description":"Integration alerts, on-call channel"}'
Response
{
  "ok": true,
  "data": {
    "id": "3f1c9a4e-7b52-4f0e-9a41-2c9d5e6b8a10",
    "url": "https://hooks.example.com/trackingmcp",
    "event_types": ["api_change_announced"],
    "description": "Integration alerts, on-call channel",
    "active": true,
    "created_at": "2026-08-07T09:12:04.881Z",
    "secret": "whsec_3f9a1c7e5b204d8619ac0f73e26b8d45a1c9e30f7b264d58"
  }
}