> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.goautolane.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.goautolane.com/_mcp/server.

# Update a webhook endpoint

PUT https://api.goautolane.com/rs/v1/webhooks/{id}
Content-Type: application/json

Changes `url`, `subscribed_events`, or `is_active`, or rotates the secret. Every field is optional, but the body must carry at least one; an empty object is `400 VALIDATION_ERROR`. Concurrent `PUT`s are last write wins: every field you send is written, so a body built from a stale `GET` can undo another caller's change and still answer `200`.

Every call needs `webhooks:manage`. Changing `url` or `subscribed_events`, or setting `is_active` to `true`, also needs `reservations:read`; a value sent back unchanged is not a change. Pausing (`is_active: false`) and rotating need `webhooks:manage` alone, so you can always stop a stream or replace a leaked secret; a `403` names the fields that asked for more.

`rotate_secret: true` returns the new secret in full exactly once. New deliveries are signed with it at once, but one already picked up keeps the old secret for up to 90 seconds, so accept both briefly. Rotation is not idempotent and `Idempotency-Key` is ignored: a retried rotate rotates again and the first secret is gone. Pausing and repointing have delivery side effects of their own; see Managing endpoints in the Reservations guide.

Reference: https://docs.goautolane.com/direct-delivery/api-reference/webhooks/update

## Authentication

- `Authorization` header (bearer token, required) — API key generated in the Autolane Portal. Keys are organization-scoped, carry granular permissions, and are environment-specific: a sandbox key only works against the sandbox host, and a production key only against the production host.

## Servers

- `https://api.goautolane.com` (Production, default)
- `https://api-sandbox.goautolane.com` (Sandbox)

## Request

### Path parameters

- `id` (string, required) — Webhook endpoint id

### Body (application/json)

This endpoint expects an UpdateWebhookBody.

- `url` (string, optional)
- `subscribed_events` (list of enum, optional)
  - Allowed values: `reservation.status_changed`, `reservation.handoff_updated`, `reservation.exception`
- `is_active` (boolean, optional)
- `rotate_secret` (boolean, optional)

## Response

### 200

The updated endpoint. Its secret is masked unless this request rotated it, in which case it is shown in full for the only time.

- `success` (boolean, required)
- `data` (WebhookResponseData, required)

## Errors

### 400 Bad Request Error

The id is not a UUID, or the body is invalid JSON, empty, or fails validation (`VALIDATION_ERROR`)

- `success` (boolean, required)
- `error` (string, required) — Human-readable error message
- `code` (string, required) — Stable machine-readable error code

### 401 Unauthorized Error

Missing or invalid API key (`INVALID_API_KEY`)

- `success` (boolean, required)
- `error` (string, required) — Human-readable error message
- `code` (string, required) — Stable machine-readable error code

### 403 Forbidden Error

Key valid but not usable here: wrong environment (`WRONG_ENV_KEY`), the organization is not enrolled as a fleet partner (`NOT_FLEET_PARTNER`), the organization is deactivated or not yet provisioned in this environment (`ORG_INACTIVE`), or a missing permission (`PERMISSION_DENIED`): every call needs `webhooks:manage`, and changing `url` or `subscribed_events` or setting `is_active` to `true` also needs `reservations:read`; the message names the fields that asked for more.

- `success` (boolean, required)
- `error` (string, required) — Human-readable error message
- `code` (string, required) — Stable machine-readable error code

### 404 Not Found Error

No such endpoint for your organization (`WEBHOOK_NOT_FOUND`)

- `success` (boolean, required)
- `error` (string, required) — Human-readable error message
- `code` (string, required) — Stable machine-readable error code

### 422 Unprocessable Entity Error

`INVALID_WEBHOOK_URL`: the new URL is not a public HTTPS endpoint

- `success` (boolean, required)
- `error` (string, required) — Human-readable error message
- `code` (string, required) — Stable machine-readable error code

### 500 Internal Server Error

Internal error (`INTERNAL_ERROR`)

- `success` (boolean, required)
- `error` (string, required) — Human-readable error message
- `code` (string, required) — Stable machine-readable error code

### 503 Service Unavailable Error

`URL_VALIDATION_UNAVAILABLE`: our capacity to validate the endpoint URL is exhausted, not a problem with your URL. Retry the same request.

- `success` (boolean, required)
- `error` (string, required) — Human-readable error message
- `code` (string, required) — Stable machine-readable error code

## Types

### WebhookResponseData

- `webhook` (WebhookEndpoint, required)

### WebhookEndpoint

- `webhook_id` (string, required)
- `url` (string, required)
- `secret` (string, required) — Shown in full only in the response that creates or rotates it; masked everywhere else
- `subscribed_events` (list of enum, required)
  - Allowed values: `reservation.status_changed`, `reservation.handoff_updated`, `reservation.exception`
- `is_active` (boolean, required)
- `created_at` (datetime, required)
- `updated_at` (datetime, required)

## Examples

**Request**

```json
{}
```

**Response**

```json
{
  "success": true,
  "data": {
    "webhook": {
      "webhook_id": "string",
      "url": "string",
      "secret": "whsec_…cdef",
      "subscribed_events": [
        "reservation.status_changed"
      ],
      "is_active": true,
      "created_at": "2024-01-15T09:30:00Z",
      "updated_at": "2024-01-15T09:30:00Z"
    }
  }
}
```

**SDK Code**

```python
import requests

url = "https://api.goautolane.com/rs/v1/webhooks/id"

payload = {}
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.put(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.goautolane.com/rs/v1/webhooks/id';
const options = {
  method: 'PUT',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.goautolane.com/rs/v1/webhooks/id"

	payload := strings.NewReader("{}")

	req, _ := http.NewRequest("PUT", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.goautolane.com/rs/v1/webhooks/id")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.put("https://api.goautolane.com/rs/v1/webhooks/id")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('PUT', 'https://api.goautolane.com/rs/v1/webhooks/id', [
  'body' => '{}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.goautolane.com/rs/v1/webhooks/id");
var request = new RestRequest(Method.PUT);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.goautolane.com/rs/v1/webhooks/id")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "PUT"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```