Skip to main content
POST
Subscribe a WebhookSource to an MCP event

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

checkfu-version
enum<string>
required
Available options:
2026-08-31
idempotency-key
string
Maximum string length: 255

Path Parameters

id
string
required
Pattern: ^auto_[0-9a-f]{32}$

Body

application/json

Subscribe one Automation WebhookSource to an authorized MCP event. Carries no callback URL or signing secret: Checkfu derives the callback and holds the key.

webhook_source_id
string
required
Pattern: ^whsrc_[0-9a-f]{32}$
expected_connection_version
integer
required
Required range: 0 < x <= 9007199254740991
descriptor_digest
string
required
Pattern: ^sha256:[0-9a-f]{64}$
event_name
string
required

The exact upstream MCP event name, compared byte for byte.

Required string length: 1 - 256
arguments
object
required

Secret-free MCP event subscription arguments of at most 16384 UTF-8 bytes, validated against the selected event's inputSchema. They are publicly readable and must not contain credentials.

Response

One inbound MCP Events webhook subscription for an Automation WebhookSource: the durable intent, its last-known remote lease and readiness. The callback route and signing key are platform-owned and never returned; a read shows last-known lease evidence, not live remote health.

One inbound MCP Events webhook subscription for an Automation WebhookSource: the durable intent, its last-known remote lease and readiness. The callback route and signing key are platform-owned and never returned; a read shows last-known lease evidence, not live remote health.

id
string
required
Pattern: ^mevsub_[0-9a-f]{32}$
workspace_id
string
required
Pattern: ^wrkspc_[0-9a-f]{32}$
automation_id
string
required
Pattern: ^auto_[0-9a-f]{32}$
webhook_source_id
string
required
Pattern: ^whsrc_[0-9a-f]{32}$
connection_id
string
required
Pattern: ^conn_[0-9a-f]{32}$
connection_version
integer
required
Required range: 0 < x <= 9007199254740991
event_name
string
required

The exact upstream MCP event name, compared byte for byte.

Required string length: 1 - 256
arguments
object
required

Secret-free MCP event subscription arguments of at most 16384 UTF-8 bytes, validated against the selected event's inputSchema. They are publicly readable and must not contain credentials.

identity_digest
string
required
Pattern: ^sha256:[0-9a-f]{64}$
descriptor_digest
string
required
Pattern: ^sha256:[0-9a-f]{64}$
status
enum<string>
required
Available options:
pending,
active,
degraded,
expired,
revoked,
failed,
deleting,
deleted
readiness
enum<string>
required
Available options:
awaiting_verification,
active,
renewal_degraded,
lease_too_short,
expired,
revoked,
needs_reconnection,
subscribe_failed,
cleanup_pending,
deleted
lease
object | null
required
last_verified_at
string | null
required

A canonical UTC ISO-8601 timestamp with millisecond precision.

Maximum string length: 24
Pattern: ^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z$
last_error
object | null
required
version
integer
required
Required range: 0 < x <= 9007199254740991
created_at
string
required

A canonical UTC ISO-8601 timestamp with millisecond precision.

Maximum string length: 24
Pattern: ^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z$
updated_at
string
required

A canonical UTC ISO-8601 timestamp with millisecond precision.

Maximum string length: 24
Pattern: ^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z$