Skip to main content
Whether the callback secret is set

Authorizations

Authorization
string
header
required

Every request sends Authorization: Bearer <token>. The token is either a panel session (a JWT from /auth/login, 12 hours) or an API key ft_<id>_<secret>. An API key is accepted only from an address on its IP allowlist (403 ip_not_allowed otherwise; 403 ip_allowlist_required for an old key that has none), is limited to its rate per minute (429 rate_limited with Retry-After; X-RateLimit-Limit/Remaining/Reset on every response), and at most 60 call placements a minute.

Query Parameters

organisation_id
string<uuid>

Narrow to one organisation. Outside your scope returns 403.

Response

200 - application/json

OK

created_at
string<date-time>
organisation_id
string
set
boolean