Register a webhook endpoint
Registers an HTTPS endpoint for reservation events. Needs webhooks:manage and reservations:read, since the endpoint receives whole reservations. The URL must resolve to a public address; we check that at registration.
The 201 is the only time the secret is shown in full. Store it: every later read masks it, and only a rotation yields a usable secret again. An organization holds at most 10 endpoints, deactivated ones included, because endpoints cannot be deleted; reuse a slot by repointing one with PUT. Idempotency-Key is ignored here, so a create retried after a lost response can register a duplicate that receives every event too; find it with GET /rs/v1/webhooks and switch it off with PUT.
Authentication
API key generated in the Autolane Portal. Keys are organization-scoped, carry granular permissions, and are environment-specific: a sandbox key only works against the sandbox host, and a production key only against the production host.