> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ontime.hosai.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Register a webhook (secret returned once)

> Register a webhook (secret returned once)



## OpenAPI

````yaml /api-reference/openapi.json post /api/api-access/webhooks
openapi: 3.1.0
info:
  title: ontime API
  description: APIs for ontime.v2
  version: 1.0.0
servers:
  - url: https://app.ontime.hosai.app
    description: Production
security:
  - apiKey: []
paths:
  /api/api-access/webhooks:
    post:
      tags:
        - API access
      summary: Register a webhook (secret returned once)
      description: Register a webhook (secret returned once)
      operationId: postApiApiAccessWebhooks
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                url:
                  type: string
                  maxLength: 500
                  format: uri
                events:
                  minItems: 1
                  type: array
                  items:
                    type: string
                    enum:
                      - leave.approved
                      - leave.rejected
                      - regularization.approved
                      - regularization.rejected
                      - overtime.approved
                      - overtime.rejected
                      - payslip.published
                      - form16.available
                      - message.received
              required:
                - url
                - events
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                    format: uuid
                    pattern: >-
                      ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                  url:
                    type: string
                  events:
                    type: array
                    items:
                      type: string
                      enum:
                        - leave.approved
                        - leave.rejected
                        - regularization.approved
                        - regularization.rejected
                        - overtime.approved
                        - overtime.rejected
                        - payslip.published
                        - form16.available
                        - message.received
                  status:
                    type: string
                    enum:
                      - Healthy
                      - Failing
                  lastDeliveryAt:
                    anyOf:
                      - type: string
                      - type: 'null'
                  createdAt:
                    type: string
                  secretHint:
                    type: string
                  secret:
                    type: string
                required:
                  - id
                  - url
                  - events
                  - status
                  - lastDeliveryAt
                  - createdAt
                  - secretHint
                  - secret
components:
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      bearerFormat: ont_ API key
      description: >-
        Issue keys in Settings → API. Send them as `Authorization: Bearer ont_…`
        (an `X-Api-Key: ont_…` header is also accepted). Session-cookie routes
        are used by the OnTime web apps and are shown for completeness.

````