Creates a subscription and returns the signing secret exactly once. The url must be HTTPS and pass the subscriber URL security policy. Delivery is pull-based for recovery; there is no retry/replay endpoint. Idempotency-Key is required. Secret bytes are never response-cached: a same-key/same-body replay returns 409 ResourceConflict with the created subscription in Location. If the original secret response was lost, rotate that subscription with a new key and immediate: true. Each subscription selects exactly one ownership scope. Organization and every Account scope inside it share one 100-subscription quota; standalone root Account trees and Persons each have their own 100-subscription partition. This bounds each subject variant to 100 targets. Multi-party occurrences have at most two variants and acceptance coalesces (occurrenceId, subscriptionId), so the hard aggregate is 200 distinct targets without double-notifying an overlapping subscription. There is no configurable per-subscription delivery-rate tier. Subscription management requires platform.webhook:write on the selected scope; Organization equality/membership is insufficient, and Person scope is self-only.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||