> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flowsign.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Flowsign is one word with a lowercase s.
> The REST API base URL is https://my.flowsign.app and every endpoint lives under /api/v1.
> When answering API questions, cite the HTTP method and endpoint path.
> API access needs the Enterprise plan and an API key with the API access permission.

# Update a webhook endpoint

> Updates any of url, description, events, or enabled. Requires canManageWebhooks.



## OpenAPI

````yaml /api-reference/openapi.json patch /api/v1/webhooks/{endpointId}
openapi: 3.0.3
info:
  title: Flowsign API
  version: 1.0.0
  description: >-
    Public v1 API for Flowsign. Every endpoint is authenticated with a Bearer
    API key (prefix `fsk_`). Errors use `{ error, details? }`; success responses
    wrap payload data as `{ data }`.


    An organisation is divided into workspaces. A key is issued for one
    workspace and acts there on every request (see `GET /api/v1/workspaces`);
    `X-Workspace-Id` is optional and may only name that workspace. Packages,
    templates, contacts and members are scoped to the key's workspace.
servers:
  - url: https://my.flowsign.app
    description: Production
security:
  - ApiKey: []
paths:
  /api/v1/webhooks/{endpointId}:
    patch:
      tags:
        - Webhooks
      summary: Update a webhook endpoint
      description: >-
        Updates any of url, description, events, or enabled. Requires
        canManageWebhooks.
      operationId: patchWebhooksByEndpointId
      parameters:
        - schema:
            type: string
          required: true
          name: endpointId
          in: path
        - schema:
            type: string
            description: >-
              The workspace the key was issued for, as returned by `GET
              /api/v1/workspaces`. Optional: omitting it acts in the key's
              workspace, and any other id is rejected with 401.
          required: false
          name: x-workspace-id
          in: header
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                url:
                  type: string
                  format: uri
                  description: >-
                    HTTPS URL to POST events to. Rejected when it is not HTTPS
                    or its host is localhost, a .local/.internal name, or a
                    private, loopback, link-local or multicast address.
                    Redirects are not followed at delivery time.
                  example: https://hooks.example.co.nz/flowsign
                description:
                  type: string
                  nullable: true
                  description: Free-text label for the endpoint. Null clears it.
                  example: Production CRM sync
                events:
                  type: array
                  items:
                    $ref: '#/components/schemas/WebhookEventType'
                  minItems: 1
                  description: Replaces the subscribed events. At least one.
                  example:
                    - PACKAGE_COMPLETED
                    - PACKAGE_DECLINED
                    - PACKAGE_VOIDED
                enabled:
                  type: boolean
                  description: >-
                    Turns delivery on or off. Setting true also resets
                    `failureCount` to 0 and sends the events held while the
                    endpoint was paused or failing, oldest first. Setting false
                    leaves queued retries as they are.
                  example: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                        description: Webhook endpoint id.
                        example: cmg1h7t2k0003v8p9d4q6xw2e
                      url:
                        type: string
                        description: HTTPS URL that receives event POSTs.
                        example: https://hooks.example.co.nz/flowsign
                      events:
                        type: array
                        items:
                          $ref: '#/components/schemas/WebhookEventType'
                        description: >-
                          Events this endpoint is subscribed to after the
                          update.
                        example:
                          - PACKAGE_COMPLETED
                          - PACKAGE_DECLINED
                          - PACKAGE_VOIDED
                      enabled:
                        type: boolean
                        description: >-
                          Whether events are delivered to this endpoint after
                          the update.
                        example: true
                      updatedAt:
                        type: string
                        description: When the endpoint was last changed (ISO 8601).
                        example: '2026-09-15T04:20:00.000Z'
                    required:
                      - id
                      - url
                      - events
                      - enabled
                      - updatedAt
                required:
                  - data
        '400':
          description: The request body is not valid JSON
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing or invalid API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '402':
          description: Caller's plan does not include this feature (publicApi / webhooks)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: API key present but caller lacks the required permission
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: No webhook endpoint with that id in the organisation
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: Request failed schema validation; details keyed by field
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limit exceeded; see `Retry-After`
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    WebhookEventType:
      type: string
      enum:
        - PACKAGE_SENT
        - PACKAGE_COMPLETED
        - PACKAGE_VOIDED
        - PACKAGE_EXPIRED
        - PACKAGE_DECLINED
        - PACKAGE_ON_HOLD
        - PACKAGE_RESUMED
        - PACKAGE_SCHEDULED
        - PACKAGE_DELETED
        - SESSION_SENT
        - SESSION_OPENED
        - SESSION_COMPLETED
        - SESSION_DECLINED
        - SESSION_REMINDED
        - SESSION_CANCELLED
      description: >-
        Event name. PACKAGE_SENT: a package was sent to its recipients.
        PACKAGE_COMPLETED: every recipient finished and the package is complete.
        PACKAGE_VOIDED: the sender voided the package. PACKAGE_EXPIRED: the
        package passed its expiry before completing. PACKAGE_DECLINED: a
        recipient declined and the package stopped. PACKAGE_ON_HOLD: the sender
        paused signing on the package. PACKAGE_RESUMED: a package on hold went
        back out for signing. PACKAGE_SCHEDULED: the package was scheduled to
        send later, or moved to a new time. PACKAGE_DELETED: a package that was
        scheduled or out for signing was deleted. SESSION_SENT: one recipient's
        signing invitation was sent. SESSION_OPENED: a recipient opened their
        signing link. SESSION_COMPLETED: a recipient finished their step.
        SESSION_DECLINED: a recipient declined their step. SESSION_REMINDED: a
        recipient was sent a reminder. SESSION_CANCELLED: a recipient's open
        signing session ended because the package was declined, voided, expired
        or deleted, or a correction removed them.
      example: PACKAGE_COMPLETED
    Error:
      type: object
      properties:
        error:
          type: string
          description: What went wrong, in plain words.
          example: 'Missing permission: canSendPackages'
        details:
          type: object
          additionalProperties:
            type: array
            items:
              type: string
          description: >-
            Validation problems keyed by field path. Present only on 422
            responses.
          example:
            recipients.0.email:
              - Invalid email
      required:
        - error
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      bearerFormat: fsk_*

````