> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanova.io/llms.txt
> Use this file to discover all available pages before exploring further.

# List / create webhooks

> GET, POST /webhook/

A **webhook** here is a generic connection row covering every integration type — plain URL-based webhooks, Zapier, and (once connected via the web app) Slack/HubSpot connections too. This lists or creates them.

<Note>
  Requires the `IntegrationCanView` (GET) or `IntegrationCanAdd` (POST) permission, which itself checks the quota named by the target `type` (see [List integration types](/api-reference/management-api/integrations/webhook-types)).
</Note>

<ParamField query="search" type="string">
  Matches against the URL, tracking id, comment/connection name, and linked lead-list/form name.
</ParamField>

<ParamField query="ordering" type="string">
  One of `created`, `modified`, `last_used_on`. Prefix with `-` to sort descending.
</ParamField>

<ParamField body="type" type="string" required>
  Integration type key, e.g. `lead`, `form`, `analytics`, `event_tracking`, `zapier`. See [List integration types](/api-reference/management-api/integrations/webhook-types) for the full set and each type's required fields.
</ParamField>

<ParamField body="urls" type="array">
  One or more target URLs. When more than one is sent on create, one webhook row is created per URL (bulk-created, only the first is returned in the response).
</ParamField>

<ParamField body="lead_list" type="integer">
  Lead list id, for lead-notification webhook types.
</ParamField>

<ParamField body="form" type="integer">
  Form id, for form-notification webhook types.
</ParamField>

<ParamField body="comment" type="string">
  Free-text label — also doubles as the searchable "connection name" for types with no other distinguishing field.
</ParamField>

<ParamField body="is_active" type="boolean">
  Whether the webhook is currently enabled.
</ParamField>

<RequestExample>
  ```bash cURL Create theme={null}
  curl --request POST \
    --url 'https://api.scanova.io/webhook/' \
    --header 'Authorization: YOUR_API_KEY' \
    --header 'Content-Type: application/json' \
    --data '{
      "type": "lead",
      "urls": ["https://example.com/hooks/lead-capture"],
      "lead_list": 12,
      "comment": "CRM sync"
    }'
  ```
</RequestExample>

<ResponseExample>
  ```json 201 theme={null}
  {
    "id": 44,
    "lead_list": 12,
    "form": null,
    "qr_code": null,
    "hubspot_connection": null,
    "tracking_id": null,
    "type": "lead",
    "url": "https://example.com/hooks/lead-capture",
    "is_active": true,
    "redirection_delay": null,
    "status": "active",
    "event_type": null,
    "last_used_on": null,
    "last_used_status": null,
    "comment": "CRM sync",
    "misc": null,
    "created": "2026-09-09T08:00:00+05:30",
    "created_by_name": "Jane Doe",
    "modified": "2026-09-09T08:00:00+05:30",
    "lead_list_name": "Storefront Leads",
    "form_name": null,
    "form_form_id": null,
    "qr_qrid": null,
    "sub_type": "lead"
  }
  ```
</ResponseExample>

<Warning>
  `secret_key` is write-only on the model but not in `WebhookSerializer`'s field list output — never rely on reading it back; store it client-side at creation time if the integration type needs one.
</Warning>

## Related

* [Retrieve / update / delete a webhook](/api-reference/management-api/integrations/webhook-retrieve)
* [List integration types](/api-reference/management-api/integrations/webhook-types) — required fields and quota per `type`.
* [Test a webhook](/api-reference/management-api/integrations/webhook-test)
* [Management API overview](/api-reference/management-api/overview) — the auth scheme and quota architecture this endpoint is part of.


## OpenAPI

````yaml api-reference/openapi/management-api.json GET /webhook/
openapi: 3.1.0
info:
  title: Scanova Management API (v2)
  description: >-
    The complete Scanova Management API — every endpoint available at
    api.scanova.io (QR codes, folders, tags, leads, forms, analytics, plans,
    shared users & roles), plus the token-creation and usage-stats endpoints
    used to authenticate against it. Every path and request/response shape below
    was verified live against a real API key and the actual running backend
    (Phase 7, 2026-08-16) — not guessed from reading urls.py alone.
  version: 2.0.0
servers:
  - url: https://api.scanova.io
    description: Management API — QR/folder/tag/lead/form/analytics/plans endpoints
security:
  - apiKeyAuth: []
paths:
  /webhook/:
    get:
      summary: List webhooks
      operationId: listManagedWebhooks
      responses:
        '200':
          description: Paginated list of webhooks.
          content:
            application/json:
              example:
                count: 1
                next: null
                previous: null
                results:
                  - id: 44
                    lead_list: 12
                    form: null
                    qr_code: null
                    hubspot_connection: null
                    tracking_id: null
                    type: lead
                    url: https://example.com/hooks/lead-capture
                    is_active: true
                    redirection_delay: null
                    status: active
                    event_type: null
                    last_used_on: null
                    last_used_status: null
                    comment: CRM sync
                    misc: null
                    created: '2026-09-09T08:00:00+05:30'
                    created_by_name: Jane Doe
                    modified: '2026-09-09T08:00:00+05:30'
                    lead_list_name: Storefront Leads
                    form_name: null
                    form_form_id: null
                    qr_qrid: null
                    sub_type: lead
components:
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Send your Management API key as the raw value of the Authorization
        header — no "Bearer " or "Token " prefix, and no other characters.
        Example: `Authorization: 401f7ac837da42b97f613d789819ff93537bee6a`. A
        header containing more than one space-separated part is rejected
        outright. Requests also require the request's Host header to be the
        management API host (e.g. api.scanova.io) — the same key sent to the
        regular API host will not authenticate.

````