openapi: 3.2.0 info: title: Relm CRM Webhooks API version: 0.17.1 summary: API-first CRM built for LLMs and AI agents. description: REST surface for Relm. contact: name: Relm url: https://relmcrm.com/ license: name: Proprietary servers: - url: https://api.relmcrm.com/v1 description: Production security: - bearerAuth: [] - oauth2: - crm tags: - name: Webhooks paths: /webhooks: get: tags: - Webhooks operationId: listWebhooks summary: List webhook subscriptions responses: '200': description: Webhooks content: application/json: schema: type: object default: $ref: '#/components/responses/Problem' post: tags: - Webhooks operationId: createWebhook summary: Subscribe an https endpoint to events. Returns the signing secret once requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/WebhookInput' responses: '201': description: Created (secret shown once) content: application/json: schema: $ref: '#/components/schemas/Webhook' default: $ref: '#/components/responses/Problem' /webhooks/{id}: parameters: - $ref: '#/components/parameters/IdPath' get: tags: - Webhooks operationId: getWebhook summary: Fetch a webhook responses: '200': description: Webhook content: application/json: schema: $ref: '#/components/schemas/Webhook' default: $ref: '#/components/responses/Problem' patch: tags: - Webhooks operationId: updateWebhook summary: Update a webhook (url/events/description/enabled) parameters: - $ref: '#/components/parameters/IfMatch' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/WebhookInput' responses: '200': description: Webhook content: application/json: schema: $ref: '#/components/schemas/Webhook' default: $ref: '#/components/responses/Problem' delete: tags: - Webhooks operationId: deleteWebhook summary: Delete a webhook responses: '200': description: Deleted content: application/json: schema: $ref: '#/components/schemas/Deleted' default: $ref: '#/components/responses/Problem' /webhooks/{id}/deliveries: parameters: - $ref: '#/components/parameters/IdPath' get: tags: - Webhooks operationId: listDeliveries summary: Recent delivery attempts (status, retries, dead-letter) responses: '200': description: Deliveries content: application/json: schema: type: object default: $ref: '#/components/responses/Problem' components: schemas: Webhook: type: object properties: id: type: string example: wh_... object: type: string const: webhook url: type: string events: type: array items: type: string description: type: - string - 'null' enabled: type: boolean secret: type: string description: whsec_...; returned ONLY on create. version: type: integer WebhookInput: type: object required: - url properties: url: type: string format: uri description: Public https endpoint (test mode allows localhost). events: type: array items: type: string description: Subset of the 5 events, or ["*"]. description: type: string enabled: type: boolean Problem: type: object description: RFC-9457 error. Closed-set rejections carry valid_options + suggestion so an agent self-corrects. properties: type: type: string format: uri example: https://relmcrm.com/errors/unknown_value title: type: string status: type: integer detail: type: string code: type: string example: unknown_value field: type: string valid_options: type: array items: type: string suggestion: type: string request_id: type: string Deleted: type: object properties: id: type: string object: type: string deleted: type: boolean responses: Problem: description: RFC-9457 problem+json error. content: application/problem+json: schema: $ref: '#/components/schemas/Problem' parameters: IfMatch: name: If-Match in: header schema: type: string description: The record's current version for optimistic concurrency; a mismatch returns 412 version_conflict. IdPath: name: id in: path required: true schema: type: string securitySchemes: bearerAuth: type: http scheme: bearer description: Workspace-scoped API key. relm_live_... (live) or relm_test_... (free, isolated test mode). Mint at https://app.relmcrm.com/. oauth2: type: oauth2 description: 'OAuth 2.1 with PKCE (S256) and dynamic client registration (RFC 7591). Live mode only; test mode is API-key only. Discovery: /.well-known/oauth-authorization-server.' flows: authorizationCode: authorizationUrl: https://api.relmcrm.com/oauth/authorize tokenUrl: https://api.relmcrm.com/oauth/token refreshUrl: https://api.relmcrm.com/oauth/token scopes: crm: Read and write the connected Relm workspace