Atualizar webhook
curl --request PATCH \
--url https://api.sandbox.z2pay.com/v1/webhooks/{id} \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"name": "<string>",
"url": "<string>",
"events": [],
"checkoutLinkIds": [
"<string>"
]
}
'const options = {
method: 'PATCH',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({name: '<string>', url: '<string>', events: [], checkoutLinkIds: ['<string>']})
};
fetch('https://api.sandbox.z2pay.com/v1/webhooks/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.sandbox.z2pay.com/v1/webhooks/{id}"
payload = {
"name": "<string>",
"url": "<string>",
"events": [],
"checkoutLinkIds": ["<string>"]
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"id": "<string>",
"name": "<string>",
"url": "<string>",
"events": [
"<string>"
],
"checkoutLinkIds": [
"<string>"
],
"isActive": true,
"hasSecret": true,
"secretHint": "<string>",
"autoDisabledAt": "2023-11-07T05:31:56Z",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z"
}{
"error": {
"code": "VALIDATION_ERROR",
"message": "Validation failed",
"issues": [
{
"path": "status",
"message": "Status inválido. Valores aceitos: pending, waiting_payment, paid, refused, canceled, refunded"
},
{
"path": "startDate",
"message": "Data deve ser ISO 8601 com timezone (ex.: 2026-06-24T00:00:00Z)"
}
]
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Invalid API key"
}
}{
"error": {
"code": "NOT_FOUND",
"message": "Webhook not found"
}
}{
"error": "A request with this idempotency key is already being processed"
}{
"error": "Idempotency key already used with a different request body"
}Webhooks
Atualizar webhook
Muda nome, URL e a lista de eventos assinados de um webhook já cadastrado.
PATCH
/
webhooks
/
{id}
Atualizar webhook
curl --request PATCH \
--url https://api.sandbox.z2pay.com/v1/webhooks/{id} \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"name": "<string>",
"url": "<string>",
"events": [],
"checkoutLinkIds": [
"<string>"
]
}
'const options = {
method: 'PATCH',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({name: '<string>', url: '<string>', events: [], checkoutLinkIds: ['<string>']})
};
fetch('https://api.sandbox.z2pay.com/v1/webhooks/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.sandbox.z2pay.com/v1/webhooks/{id}"
payload = {
"name": "<string>",
"url": "<string>",
"events": [],
"checkoutLinkIds": ["<string>"]
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"id": "<string>",
"name": "<string>",
"url": "<string>",
"events": [
"<string>"
],
"checkoutLinkIds": [
"<string>"
],
"isActive": true,
"hasSecret": true,
"secretHint": "<string>",
"autoDisabledAt": "2023-11-07T05:31:56Z",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z"
}{
"error": {
"code": "VALIDATION_ERROR",
"message": "Validation failed",
"issues": [
{
"path": "status",
"message": "Status inválido. Valores aceitos: pending, waiting_payment, paid, refused, canceled, refunded"
},
{
"path": "startDate",
"message": "Data deve ser ISO 8601 com timezone (ex.: 2026-06-24T00:00:00Z)"
}
]
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Invalid API key"
}
}{
"error": {
"code": "NOT_FOUND",
"message": "Webhook not found"
}
}{
"error": "A request with this idempotency key is already being processed"
}{
"error": "Idempotency key already used with a different request body"
}PATCH /webhooks/:id
Faz parte do recurso Webhooks — o cadastro e o catálogo de eventos estão lá.
Atualiza o que já está cadastrado. Todos os campos são opcionais: envie só o que muda, o resto
permanece.
events substitui a lista inteira — e [] assina TUDO. Não há como acrescentar ou remover
um evento isoladamente: mande a lista final que você quer. E cuidado com o vazio, que é curinga,
não “nenhum”: events: [] faz o webhook receber todos os eventos existentes e futuros. Para
parar de receber, desative o webhook.O
secret não se troca aqui, nem em nenhuma outra rota. O campo não é aceito no corpo, e não
existe endpoint de rotação — a troca é feita no painel. Pela API, o equivalente é
criar um webhook novo com o mesmo destino e
remover o antigo.Trocar a URL não reenvia o que já falhou. As entregas anteriores guardam o endereço para o
qual saíram; o novo vale das próximas em diante. Para recuperar o que se perdeu, use
Reprocessar entrega — ela sai para a URL atual.
Exemplo
curl -X PATCH https://api.sandbox.z2pay.com/v1/webhooks/whk_k9clfafnldd96dbbxruh34233 \
-H "x-api-key: SUA_CHAVE_DE_SANDBOX" \
-H "Content-Type: application/json" \
-d '{
"events": ["transaction.paid", "transaction.refused", "transaction.refunded"]
}'
Resposta 200
{
"id": "whk_k9clfafnldd96dbbxruh34233",
"name": "Notificações de pagamento",
"url": "https://meusite.com/webhooks/z2pay",
"events": ["transaction.paid", "transaction.refused", "transaction.refunded"],
"isActive": true,
"hasSecret": true,
"secretHint": "whsec_kQ8v…rS8t",
"autoDisabledAt": null,
"createdAt": "2026-06-24T13:45:00.000Z",
"updatedAt": "2026-06-24T14:10:00.000Z"
}
Authorizations
API Key da Credential (gerada no Backoffice)
Headers
Chave única para garantir idempotência da requisição
Path Parameters
ID do webhook
Body
application/json
Required string length:
1 - 255Available options:
transaction.created, transaction.waiting_payment, transaction.paid, transaction.partially_paid, transaction.pending, transaction.refused, transaction.failed, transaction.canceled, transaction.waiting_refund, transaction.refunded, transaction.in_protest, transaction.chargeback, payment.created, payment.waiting_payment, payment.paid, payment.pending, payment.refused, payment.failed, payment.canceled, payment.waiting_refund, payment.refunded, payment.in_protest, payment.chargeback, refund.created, refund.approved, refund.refused, refund.processing, refund.refunded, refund.failed, refund.awaiting_bank_details, refund.bank_details_received, refund.invalid_bank_details, refund.ted_processing, chargeback.opened, chargeback.under_review, chargeback.submitted, chargeback.won, chargeback.lost, chargeback.document.uploaded, customer.created, customer.updated, recipient.created, recipient.updated, recipient.approved, recipient.refused, recipient.deleted, recipient.pendency_updated, withdrawal.requested, withdrawal.paid, withdrawal.rejected, invoice.issued, invoice.payment_attempted, invoice.paid, invoice.voided, invoice.refunded, invoice.rescheduled, extra_item.created, extra_item.canceled, extra_item.billed, subscription.created, subscription.trial_started, subscription.activated, subscription.canceled, subscription.cycle_advanced, subscription.paused, subscription.resumed, subscription.past_due, subscription.unpaid, subscription.restored, subscription.reactivated, subscription.plan_changed, subscription.plan_change_scheduled, subscription.plan_change_canceled, anticipation.status_changed IDs de checkout links (chk_...) cujos eventos este webhook recebe. Lista vazia ou omitida = eventos de todos os checkouts. Com filtro, eventos sem vínculo de checkout (ex.: venda direta por API) não são entregues.
Maximum array length:
100Pattern:
^chk_[A-Za-z0-9]+$Response
Webhook atualizado
Identificador único do registro.
Nome do registro.
URL de destino do webhook ou link de download do arquivo.
Tipos de evento assinados pelo webhook.
Indica se o registro está ativo.
Data e hora de criação do registro (ISO 8601).
Data e hora da última atualização do registro (ISO 8601).