> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.messageblue.ai/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.messageblue.ai/_mcp/server.

# Set your webhook URLs

POST https://api.messageblue.ai/settings/webhooks
Content-Type: application/json

Register where MessageBlue delivers your events.

- `inboundWebhookUrl` receives `inbound_message` and `inbound_reaction` events.
- `statusWebhookUrl` receives delivery-status updates for outbound messages. A per-message `status_callback`, if you set one when sending, takes precedence over this account-level URL.

Both fields are optional; send only the one you want to change. Passing an empty value unsets that webhook and the account falls back to default behavior. Every delivery to these URLs is signed — see the **Webhooks** tag for the verification scheme.

Reference: https://docs.messageblue.ai/api-reference/webhooks/update-webhooks

## OpenAPI Specification

```yaml
openapi: 3.1.0
info:
  title: swagger
  version: 1.0.0
paths:
  /settings/webhooks:
    post:
      operationId: updateWebhooks
      summary: Set your webhook URLs
      description: >-
        Register where MessageBlue delivers your events.


        - `inboundWebhookUrl` receives `inbound_message` and `inbound_reaction`
        events.

        - `statusWebhookUrl` receives delivery-status updates for outbound
        messages. A per-message `status_callback`, if you set one when sending,
        takes precedence over this account-level URL.


        Both fields are optional; send only the one you want to change. Passing
        an empty value unsets that webhook and the account falls back to default
        behavior. Every delivery to these URLs is signed — see the **Webhooks**
        tag for the verification scheme.
      tags:
        - webhooks
      parameters:
        - name: X-App-Id
          in: header
          description: >-
            Your MessageBlue App ID, sent in clear on every request. It is
            paired with request signing: each request is also signed with your
            App Secret (see the **Authentication** tag). The App Secret itself
            is NEVER transmitted — it is only the HMAC signing key.
          required: true
          schema:
            type: string
      responses:
        '200':
          description: Updated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UpdateWebhooksResponse'
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized (HMAC)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WebhooksUpdateRequest'
servers:
  - url: https://api.messageblue.ai
    description: Production
  - url: http://localhost:8080
    description: Local development
components:
  schemas:
    WebhooksUpdateRequest:
      type: object
      properties:
        inboundWebhookUrl:
          type:
            - string
            - 'null'
          format: uri
          description: >-
            Destination for inbound_message and inbound_reaction events. Empty
            value unsets it.
        statusWebhookUrl:
          type:
            - string
            - 'null'
          format: uri
          description: Destination for delivery-status events. Empty value unsets it.
      title: WebhooksUpdateRequest
    UpdateWebhooksResponse:
      type: object
      properties:
        message:
          type: string
        inboundWebhookUrl:
          type:
            - string
            - 'null'
          format: uri
        statusWebhookUrl:
          type:
            - string
            - 'null'
          format: uri
      title: UpdateWebhooksResponse
    FieldError:
      type: object
      properties:
        field:
          type: string
        issue:
          type: string
        message:
          type: string
      required:
        - field
        - issue
        - message
      title: FieldError
    ErrorResponseErrorDetails0:
      type: array
      items:
        $ref: '#/components/schemas/FieldError'
      title: ErrorResponseErrorDetails0
    ErrorResponseErrorDetails:
      oneOf:
        - $ref: '#/components/schemas/ErrorResponseErrorDetails0'
        - type: object
          additionalProperties:
            description: Any type
      description: Field validation errors (array) or domain-specific context (object).
      title: ErrorResponseErrorDetails
    ErrorResponseError:
      type: object
      properties:
        code:
          type: string
        message:
          type: string
        requestId:
          type: string
          format: uuid
        details:
          $ref: '#/components/schemas/ErrorResponseErrorDetails'
          description: Field validation errors (array) or domain-specific context (object).
      required:
        - code
        - message
        - requestId
      title: ErrorResponseError
    ErrorResponse:
      type: object
      properties:
        ok:
          type: boolean
        error:
          $ref: '#/components/schemas/ErrorResponseError'
      required:
        - ok
        - error
      title: ErrorResponse
  securitySchemes:
    appId:
      type: apiKey
      in: header
      name: X-App-Id
      description: >-
        Your MessageBlue App ID, sent in clear on every request. It is paired
        with request signing: each request is also signed with your App Secret
        (see the **Authentication** tag). The App Secret itself is NEVER
        transmitted — it is only the HMAC signing key.

```

## Examples



**Request**

```json
{}
```

**Response**

```json
{
  "message": "Webhook updated successfully",
  "inboundWebhookUrl": "https://hooks.myapp.com/inbound",
  "statusWebhookUrl": "https://hooks.myapp.com/status"
}
```

**SDK Code**

```python
import requests

url = "https://api.messageblue.ai/settings/webhooks"

payload = {}
headers = {
    "X-App-Id": "<apiKey>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.messageblue.ai/settings/webhooks';
const options = {
  method: 'POST',
  headers: {'X-App-Id': '<apiKey>', 'Content-Type': 'application/json'},
  body: '{}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.messageblue.ai/settings/webhooks"

	payload := strings.NewReader("{}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("X-App-Id", "<apiKey>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.messageblue.ai/settings/webhooks")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["X-App-Id"] = '<apiKey>'
request["Content-Type"] = 'application/json'
request.body = "{}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.messageblue.ai/settings/webhooks")
  .header("X-App-Id", "<apiKey>")
  .header("Content-Type", "application/json")
  .body("{}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.messageblue.ai/settings/webhooks', [
  'body' => '{}',
  'headers' => [
    'Content-Type' => 'application/json',
    'X-App-Id' => '<apiKey>',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.messageblue.ai/settings/webhooks");
var request = new RestRequest(Method.POST);
request.AddHeader("X-App-Id", "<apiKey>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "X-App-Id": "<apiKey>",
  "Content-Type": "application/json"
]
let parameters = [] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.messageblue.ai/settings/webhooks")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```