Update webhook
Update webhook
Overview
Update webhook
Patches delivery URL, secrets, subscribed events, or lifecycle flags for an existing subscription.
When to use this
Use when rotating signing secrets without re-creating the endpoint record.
Good to know
Coordinate secret rotation with your receiver to avoid rejecting signed payloads.
See also
Authentication
Merchant routes require an API key in the X-API-KEY header (see Integration overview). Use a test key against https://sandbox.api.lomi.africa and a live key against https://api.lomi.africa.
Endpoint
PATCH /webhooks/{id}
Base URLs:
https://sandbox.api.lomi.africahttps://api.lomi.africa
Request
Path parameters
No path parameters beyond the URL pattern.
Query parameters
No query parameters.
Request body
JSON request payload.
Schema: object
| Field | Required | Type | Description |
|---|---|---|---|
url | No | string | - |
is_active | No | boolean | - |
authorized_events | No | array<string> | - |
metadata | No | object | - |
Example body:
{
"url": "string",
"is_active": true,
"authorized_events": [
"string"
]
}Responses
| Status | Description |
|---|---|
200 | Success |
Errors
Errors follow the standard JSON error format (status code and machine-readable message). Validate inputs before calling; 401 indicates a missing/invalid key, 404 a missing resource for this organization, 429 rate limiting. For safe retries on create-style calls, send an idempotency key when your flow supports it.
Example
curl -sS -X PATCH "https://sandbox.api.lomi.africa/webhooks/id_value" \
-H "X-API-KEY: $LOMI_SECRET_KEY" \
-H "Content-Type: application/json" \
-d '{"url":"string","is_active":true,"authorized_events":["string"]}'OpenAPI
- operationId:
WebhooksController_update - Operation:
PATCH /webhooks/{id}
Full schemas and Try it: API reference. Machine-readable contract: repo apps/docs/openapi.json.