POST request to a URL of your choosing, containing a JSON payload with full details about the event. You can register multiple webhook endpoints, each subscribed to a different set of events, giving you fine-grained control over which parts of your system are notified about which activity.
Supported Events
The following events can be subscribed to when you register a webhook endpoint. Each event name corresponds to a specific action taken within your account.Payload Structure
All events share a common JSON envelope, with a top-levelevent field identifying the event type and a data field containing the relevant object. Your endpoint will always receive a Content-Type: application/json header alongside the payload body.
POST /v1/webhooks
Register a new webhook endpoint that will receive event notifications. You can subscribe each endpoint to one or more of the supported event types. Optionally, you can provide a secret that Google will use to sign every payload, allowing your server to verify the request is authentic. This endpoint requires write scope and returns201 Created on success.
Request Body
string
required
The publicly accessible HTTPS URL to which Google will send event payloads. The URL must respond with a
2xx status code within 10 seconds to be considered a successful delivery. HTTP URLs are not accepted — your endpoint must use HTTPS.array
required
An array of event name strings to subscribe this endpoint to. At least one event name is required. Valid values are
data.created, data.updated, data.deleted, and user.created. Pass ["*"] to subscribe to all current and future events.string
An optional secret string used to generate an HMAC-SHA256 signature for each outgoing payload. When provided, Google includes a
X-Google-Signature header on every request so your server can verify the payload’s authenticity. See Verifying Webhook Signatures below.Example Request
Example Response
Response Fields
string
The unique identifier for the newly registered webhook, prefixed with
wh_.string
The HTTPS URL that will receive event payloads.
array
The list of event names this endpoint is subscribed to, as provided in the request body.
string
The current status of the webhook. Newly registered webhooks start as
active.string
The ISO 8601 timestamp at which the webhook was registered, in UTC.
GET /v1/webhooks
Retrieve a list of all webhook endpoints currently registered to your account, including their subscribed events and status.Example Request
Example Response
Response Fields
array
An array of registered webhook endpoint objects.
integer
The total number of webhook endpoints registered to your account.
DELETE /v1/webhooks/
Remove a registered webhook endpoint from your account. Once deleted, no further event payloads will be sent to that URL. This endpoint returns204 No Content on success with an empty response body.
Path Parameters
string
required
The unique identifier of the webhook to remove, for example
wh_abc123. You can retrieve this from the GET /v1/webhooks listing.Example Request
204 No Content with no body.
Response Fields
This endpoint returns no response body. A204 No Content status code confirms the webhook endpoint was successfully removed.
Verifying Webhook Signatures
If you provided asecret when registering your webhook, Google signs the raw JSON payload body using HMAC-SHA256 and includes the resulting hex digest in the X-Google-Signature request header. You should always verify this signature before processing the event to confirm the request genuinely originated from Google and was not tampered with in transit.
Always compare signatures using a timing-safe equality function (such as
hmac.compare_digest in Python or crypto.timingSafeEqual in Node.js) to prevent timing-based attacks.If your endpoint does not return a
2xx response within 10 seconds, Google treats the delivery as failed and retries it up to 5 times using exponential backoff. Retry intervals are approximately 1 min, 5 min, 30 min, 2 hours, and 8 hours. After 5 failed attempts, no further retries are made and the webhook endpoint may be automatically disabled.