> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getaptly.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set or update the board's webhook

> Sets the board's webhook URL. Calling this again re-points an existing webhook (an
update) rather than creating a second one — a board has at most one webhook.

A new `webhookSigningKey` is generated every time this is called, including on
update, so re-pointing a webhook also rotates its signing key.




## OpenAPI

````yaml /openapi.yaml post /api/board/{boardId}/webhook
openapi: 3.0.3
info:
  title: Aptly API
  version: '1.1'
  description: |
    The Aptly API lets external systems work with boards, contacts, inboxes,
    tasks, files, and other Aptly resources.

    Most endpoints accept an API key in the `x-token` header. Some endpoints
    also accept a delegate token or partner bearer token, as shown in each
    operation's security requirements, and explicitly public endpoints require
    no credential. API keys are scoped to a company and may be restricted to
    specific boards and read, insert, or update permissions; requests outside
    those restrictions receive a 403 `FORBIDDEN` response.
servers:
  - url: https://core-api.getaptly.com
    description: Production
security:
  - ApiKeyHeader: []
paths:
  /api/board/{boardId}/webhook:
    post:
      tags:
        - Board
      summary: Set or update the board's webhook
      description: >
        Sets the board's webhook URL. Calling this again re-points an existing
        webhook (an

        update) rather than creating a second one — a board has at most one
        webhook.


        A new `webhookSigningKey` is generated every time this is called,
        including on

        update, so re-pointing a webhook also rotates its signing key.
      operationId: setBoardWebhook
      parameters:
        - name: boardId
          in: path
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - webhookUrl
              properties:
                webhookUrl:
                  type: string
                  description: Must be a valid http or https URL.
      responses:
        '201':
          description: Webhook set.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      webhookUrl:
                        type: string
                      webhookSigningKey:
                        type: string
                        description: Shared secret used to sign the webhook payload.
        '400':
          description: Missing or invalid `webhookUrl`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Invalid or missing API key.
        '403':
          description: >-
            API access is disabled for this board, or the key lacks
            insert/update permission.
        '404':
          description: Board not found.
      security:
        - ApiKeyHeader: []
        - DelegateToken: []
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
        message:
          type: string
  securitySchemes:
    ApiKeyHeader:
      type: apiKey
      in: header
      name: x-token
    DelegateToken:
      type: apiKey
      in: header
      name: Authorization
      description: 'Delegate token issued by the platform. Format: `DelegateToken <token>`'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.