openapi: 3.2.0 info: title: PostalForm Projects Public Webhook Endpoints API version: '2026-05-06' description: Public PostalForm Projects API for customer SDKs. Includes document uploads, quotes, mail orders, credits, API keys, and signed customer webhooks. servers: - url: https://projects.postalform.com tags: - name: Webhook Endpoints paths: /api/v1/webhook-endpoints: get: summary: List customer webhook endpoints for the workspace security: - bearerAuth: [] responses: '200': description: Endpoints. content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/WebhookEndpoint' operationId: listWebhookEndpoints tags: - Webhook Endpoints post: summary: Configure a customer webhook endpoint for status events security: - bearerAuth: [] requestBody: required: true content: application/json: schema: type: object properties: url: type: string format: uri pattern: ^https:// description: HTTPS endpoint that receives signed PostalForm status webhooks. signing_secret: type: string description: Optional. Generated if omitted. required: - url responses: '200': description: Created endpoint. content: application/json: schema: $ref: '#/components/schemas/WebhookEndpointSecretResponse' operationId: createWebhookEndpoint tags: - Webhook Endpoints /api/v1/webhook-endpoints/{endpoint_id}: delete: summary: Disable a customer webhook endpoint security: - bearerAuth: [] parameters: - name: endpoint_id in: path required: true schema: type: string responses: '200': description: Disabled endpoint. content: application/json: schema: $ref: '#/components/schemas/WebhookEndpoint' operationId: disableWebhookEndpoint tags: - Webhook Endpoints /api/v1/webhook-endpoints/{endpoint_id}/rotate-secret: post: summary: Rotate a customer webhook endpoint signing secret description: Returns the new signing secret once. Store it securely; list endpoints does not expose secrets. security: - bearerAuth: [] parameters: - name: endpoint_id in: path required: true schema: type: string responses: '200': description: Rotated endpoint signing secret. content: application/json: schema: $ref: '#/components/schemas/WebhookEndpointSecretResponse' operationId: rotateWebhookEndpointSecret tags: - Webhook Endpoints components: schemas: WebhookEndpointSecretResponse: type: object properties: id: type: string url: type: string format: uri pattern: ^https:// status: type: string created_at: type: string format: date-time signing_secret: type: string description: Returned only when the endpoint is created or its signing secret is rotated. WebhookEndpoint: type: object properties: id: type: string url: type: string format: uri pattern: ^https:// status: type: string created_at: type: string format: date-time securitySchemes: bearerAuth: type: http scheme: bearer