> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qa.esectra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Handles `POST /v1/webhooks/endpoints`.

> # Errors

Returns `401` without usable credentials, `422` for an unusable endpoint,
and `500` when the store fails.



## OpenAPI

````yaml /openapi.json post /v1/webhooks/endpoints
openapi: 3.1.0
info:
  title: Esectra API
  description: >-
    Transaction screening, identity verification, and wallet risk.


    Every create route accepts `Idempotency-Key`; replaying one returns the
    original record with `200` where the first call returned `201`. `POST
    /v1/transactions` requires the header, because a duplicated transaction is a
    duplicated financial record.
  license:
    name: proprietary
    identifier: proprietary
  version: 0.1.0
servers:
  - url: https://qa.esectra.com
    description: Esectra QA Documentation
security: []
paths:
  /v1/webhooks/endpoints:
    post:
      tags:
        - Webhooks
      summary: Handles `POST /v1/webhooks/endpoints`.
      description: >-
        # Errors


        Returns `401` without usable credentials, `422` for an unusable
        endpoint,

        and `500` when the store fails.
      operationId: create_endpoint_handler
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/EndpointRequestBody'
        required: true
      responses:
        '201':
          description: The endpoint, with its signing secret
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EndpointBody'
        '401':
          description: No usable credentials
        '422':
          description: The URL is not acceptable
        '503':
          description: A backing store could not be reached
      security:
        - api_key: []
        - session_cookie: []
components:
  schemas:
    EndpointRequestBody:
      type: object
      description: Endpoint registration request body.
      required:
        - url
        - secret
      properties:
        event_types:
          type: array
          items:
            type: string
          description: Event names wanted. Empty or absent means every event.
        secret:
          type: string
          description: Shared secret used to sign payloads.
        url:
          type: string
          description: Destination URL.
    EndpointBody:
      type: object
      description: An endpoint as returned to a customer, without its secret.
      required:
        - endpoint_id
        - url
        - event_types
        - active
        - created_at
      properties:
        active:
          type: boolean
          description: Whether deliveries are attempted.
        created_at:
          type: string
          description: RFC 3339 creation timestamp.
        endpoint_id:
          type: string
          description: Endpoint identifier.
        event_types:
          type: array
          items:
            type: string
          description: Event names wanted; empty means every event.
        url:
          type: string
          description: Destination URL.
  securitySchemes:
    api_key:
      type: http
      scheme: bearer
      description: >-
        A tenant API key. Acts for exactly one tenant and cannot conclude a
        case, because a conclusion records a person.
    session_cookie:
      type: apiKey
      in: cookie
      name: esectra_session
      description: >-
        A signed-in reviewer's session. httpOnly and SameSite=Lax; set by `POST
        /v1/control/sessions` and only usable once the second factor is met.

````