Skip to content

Register an HTTPS address to be sent events as they happen: a signed JSON POST for each, retried for hours if the receiver does not answer with a 2xx. events lists the event types, or leave it out for all.

POST/workspaces/{workspace}/hooks

Without a secret, g1t makes one and returns it once. A ping is sent at once. The Admin role, for a repository; owners, for a workspace.

A ping is sent before the response, so last_status is usually set already. When g1t made the signing secret, secret holds it: it is shown only this once. See webhooks.

Name Type Required Description
workspace string Yes Instead of repo: the workspace, for its own webhooks.

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
url string Yes An HTTPS address on the public internet.
events array of strings No Event types to send. All of them if left out. One of the 35 webhook event types.
secret string No What deliveries are signed with. g1t makes one if left out.
curl -X POST https://api.g1t.sh/workspaces/flagon-io/hooks \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"url": "https://hooks.example.com/g1t"
}'

A successful request answers 200 with:

{
"hook": {
"id": "hk_01kpx5p9s4h0t1w6x8y2a3b4cd",
"scope": "workspace",
"workspace": "flagon-io",
"repo": null,
"url": "https://hooks.example.com/g1t",
"events": [
"*"
],
"active": true,
"secret_hint": "…9c2e",
"created_by": "syntaqx",
"created_at": "2026-10-04T15:42:07.318Z",
"last_status": "delivered",
"last_delivered_at": "2026-10-04T15:42:07.611Z"
},
"secret": "whsec_…"
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.