curl --request POST \
--url https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'checkfu-version: <checkfu-version>' \
--data '
{
"webhook_source_id": "<string>",
"expected_connection_version": 4503599627370495,
"descriptor_digest": "<string>",
"event_name": "<string>",
"arguments": {}
}
'import requests
url = "https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions"
payload = {
"webhook_source_id": "<string>",
"expected_connection_version": 4503599627370495,
"descriptor_digest": "<string>",
"event_name": "<string>",
"arguments": {}
}
headers = {
"checkfu-version": "<checkfu-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'checkfu-version': '<checkfu-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
webhook_source_id: '<string>',
expected_connection_version: 4503599627370495,
descriptor_digest: '<string>',
event_name: '<string>',
arguments: {}
})
};
fetch('https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'webhook_source_id' => '<string>',
'expected_connection_version' => 4503599627370495,
'descriptor_digest' => '<string>',
'event_name' => '<string>',
'arguments' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"checkfu-version: <checkfu-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions"
payload := strings.NewReader("{\n \"webhook_source_id\": \"<string>\",\n \"expected_connection_version\": 4503599627370495,\n \"descriptor_digest\": \"<string>\",\n \"event_name\": \"<string>\",\n \"arguments\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions")
.header("checkfu-version", "<checkfu-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"webhook_source_id\": \"<string>\",\n \"expected_connection_version\": 4503599627370495,\n \"descriptor_digest\": \"<string>\",\n \"event_name\": \"<string>\",\n \"arguments\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"webhook_source_id\": \"<string>\",\n \"expected_connection_version\": 4503599627370495,\n \"descriptor_digest\": \"<string>\",\n \"event_name\": \"<string>\",\n \"arguments\": {}\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"workspace_id": "<string>",
"automation_id": "<string>",
"webhook_source_id": "<string>",
"connection_id": "<string>",
"connection_version": 4503599627370495,
"event_name": "<string>",
"arguments": {},
"identity_digest": "<string>",
"descriptor_digest": "<string>",
"status": "pending",
"readiness": "awaiting_verification",
"lease": {
"remote_subscription_id": "<string>",
"expires_at": "<string>",
"renew_at": "<string>",
"last_renewed_at": "<string>",
"replay": "none",
"history_gap": true
},
"last_verified_at": "<string>",
"last_error": {
"code": "<string>",
"at": "<string>"
},
"version": 4503599627370495,
"created_at": "<string>",
"updated_at": "<string>"
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.not_found",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-not-found"
}
}{
"error": {
"type": "validation.conflict",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-conflict"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}{
"error": {
"type": "runtime.provider_host_unavailable",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-provider-host-unavailable"
}
}Subscribe a WebhookSource to an MCP event
Create an McpEventSubscription for one Automation WebhookSource whose Connection is a remote MCP server under mcp-oauth custody.
curl --request POST \
--url https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'checkfu-version: <checkfu-version>' \
--data '
{
"webhook_source_id": "<string>",
"expected_connection_version": 4503599627370495,
"descriptor_digest": "<string>",
"event_name": "<string>",
"arguments": {}
}
'import requests
url = "https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions"
payload = {
"webhook_source_id": "<string>",
"expected_connection_version": 4503599627370495,
"descriptor_digest": "<string>",
"event_name": "<string>",
"arguments": {}
}
headers = {
"checkfu-version": "<checkfu-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'checkfu-version': '<checkfu-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
webhook_source_id: '<string>',
expected_connection_version: 4503599627370495,
descriptor_digest: '<string>',
event_name: '<string>',
arguments: {}
})
};
fetch('https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'webhook_source_id' => '<string>',
'expected_connection_version' => 4503599627370495,
'descriptor_digest' => '<string>',
'event_name' => '<string>',
'arguments' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"checkfu-version: <checkfu-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions"
payload := strings.NewReader("{\n \"webhook_source_id\": \"<string>\",\n \"expected_connection_version\": 4503599627370495,\n \"descriptor_digest\": \"<string>\",\n \"event_name\": \"<string>\",\n \"arguments\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions")
.header("checkfu-version", "<checkfu-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"webhook_source_id\": \"<string>\",\n \"expected_connection_version\": 4503599627370495,\n \"descriptor_digest\": \"<string>\",\n \"event_name\": \"<string>\",\n \"arguments\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/automations/{id}/mcp-event-subscriptions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"webhook_source_id\": \"<string>\",\n \"expected_connection_version\": 4503599627370495,\n \"descriptor_digest\": \"<string>\",\n \"event_name\": \"<string>\",\n \"arguments\": {}\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"workspace_id": "<string>",
"automation_id": "<string>",
"webhook_source_id": "<string>",
"connection_id": "<string>",
"connection_version": 4503599627370495,
"event_name": "<string>",
"arguments": {},
"identity_digest": "<string>",
"descriptor_digest": "<string>",
"status": "pending",
"readiness": "awaiting_verification",
"lease": {
"remote_subscription_id": "<string>",
"expires_at": "<string>",
"renew_at": "<string>",
"last_renewed_at": "<string>",
"replay": "none",
"history_gap": true
},
"last_verified_at": "<string>",
"last_error": {
"code": "<string>",
"at": "<string>"
},
"version": 4503599627370495,
"created_at": "<string>",
"updated_at": "<string>"
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.not_found",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-not-found"
}
}{
"error": {
"type": "validation.conflict",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-conflict"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}{
"error": {
"type": "runtime.provider_host_unavailable",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-provider-host-unavailable"
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
2026-08-31 255Path Parameters
^auto_[0-9a-f]{32}$Body
Subscribe one Automation WebhookSource to an authorized MCP event. Carries no callback URL or signing secret: Checkfu derives the callback and holds the key.
^whsrc_[0-9a-f]{32}$0 < x <= 9007199254740991^sha256:[0-9a-f]{64}$The exact upstream MCP event name, compared byte for byte.
1 - 256Secret-free MCP event subscription arguments of at most 16384 UTF-8 bytes, validated against the selected event's inputSchema. They are publicly readable and must not contain credentials.
Show child attributes
Show child attributes
Response
One inbound MCP Events webhook subscription for an Automation WebhookSource: the durable intent, its last-known remote lease and readiness. The callback route and signing key are platform-owned and never returned; a read shows last-known lease evidence, not live remote health.
One inbound MCP Events webhook subscription for an Automation WebhookSource: the durable intent, its last-known remote lease and readiness. The callback route and signing key are platform-owned and never returned; a read shows last-known lease evidence, not live remote health.
^mevsub_[0-9a-f]{32}$^wrkspc_[0-9a-f]{32}$^auto_[0-9a-f]{32}$^whsrc_[0-9a-f]{32}$^conn_[0-9a-f]{32}$0 < x <= 9007199254740991The exact upstream MCP event name, compared byte for byte.
1 - 256Secret-free MCP event subscription arguments of at most 16384 UTF-8 bytes, validated against the selected event's inputSchema. They are publicly readable and must not contain credentials.
Show child attributes
Show child attributes
^sha256:[0-9a-f]{64}$^sha256:[0-9a-f]{64}$pending, active, degraded, expired, revoked, failed, deleting, deleted awaiting_verification, active, renewal_degraded, lease_too_short, expired, revoked, needs_reconnection, subscribe_failed, cleanup_pending, deleted Show child attributes
Show child attributes
A canonical UTC ISO-8601 timestamp with millisecond precision.
24^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z$Show child attributes
Show child attributes
0 < x <= 9007199254740991A canonical UTC ISO-8601 timestamp with millisecond precision.
24^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z$A canonical UTC ISO-8601 timestamp with millisecond precision.
24^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z$