Developers
Using the API

Webhooks

Register a target URL so NoCFO can POST events instead of you polling.

Webhook subscriptions are per business. {business_slug} comes from list businesses.

Webhook subscriptions - List is GET /v1/business/{business_slug}/webhook_subscriptions/. It is paginated.

Webhook subscription - Create is the POST on that path. The schema requires:

FieldMeaning
nameA name for this subscription.
target_urlWhere NoCFO sends the webhook.
basic_auth_usernameUsername your endpoint expects on the delivery request.

basic_auth_password and is_active are on the schema. Read the reference page before you omit them. Send Idempotency-Key on the POST so a retry does not create two subscriptions. See Idempotency.

Retrieve, replace, update, and delete are separate operations under /webhook_subscriptions/{subscription_id}/. subscription_id comes from the list or the create response.

Your endpoint should authenticate the delivery with the basic-auth username you registered. Do not treat an unsigned call to target_url as a NoCFO event if the credentials do not match.