# Create webhook

`POST https://api.cryptohopper.com/v1/api/webhooks`

Part of [Webhooks](https://www.cryptohopper.com/api-documentation/api-reference/webhooks.md) in the Cryptohopper API reference.

Registers a URL that receives notifications for your app, or updates the message types when your app already has a webhook with that URL. Deliveries only go to users who granted your app the notifications scope.

message_types is one comma-separated string. Types: trade_completed, trade_error, order_cancelled, order_placed, config_error, on_first_start, on_trigger, on_panic_start, on_panic_end, aibot_proposal. With validation_code, Cryptohopper first POSTs to the URL, which must start with https:// and answer HTTP 200 with exactly that code as the body. Only https:// URLs receive deliveries. Each delivery is a JSON POST with an X-Hub-Signature header: the HMAC-SHA512 of the body, keyed with your app's client secret. Needs a valid access token; no scope is checked.

## Headers

| Name | Type | Required | Description |
|---|---|---|---|
| `access-token` | string | yes | The OAuth access token of the user. |

## Request body

| Field | Type | Required | Description |
|---|---|---|---|
| `webhook_url` | string | yes |  |
| `message_types` | string | yes |  |
| `validation_code` | string | no |  |

## Example request

```bash
curl -X POST "https://api.cryptohopper.com/v1/api/webhooks" \
  -H "access-token: YOUR_ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"webhook_url":"https://example.com/cryptohopper/webhook","message_types":"trade_completed,order_placed,config_error","validation_code":"a1b2c3d4"}'
```

## Response

Example response (illustrative values):

```json
{
    "data": {
        "message": "Webhook has been created.",
        "id": 1234,
        "webhook_url": "https://example.com/cryptohopper/webhook",
        "message_types": [
            "trade_completed",
            "order_placed",
            "config_error"
        ]
    }
}
```

Status codes: 200. Errors return JSON with `status`, `error` and `message`, plus a numeric `code` when the error comes from the API itself rather than the gateway.
