Managing API Endpoints (Webhooks)¶
Create, update, and delete webhook handles in Canopy. A handle is the public HTTP URL. Processing is attached later with a Trigger.
Log in at /canopy/polyui/login (for example https://na1.polyapi.io/canopy/polyui/login).
Note
You must have the “Manage Webhooks” permission.
Contact your tenant administrator or support@polyapi.io if you need it.
Create a webhook¶
Click Webhooks in the sidebar, then + Create.
Fill in identity first: Name (for example TestWebhook), Context (for example test), optional description, Visibility (ENVIRONMENT is fine for a first test).
Method for this walkthrough: POST. Leave Slug and Subpath blank unless you need path/query templates (Webhook URL Parameters).
Event Payload and Response¶
These two fields are the usual source of confusion. They are optional.
Event Payload is a sample body used to derive a stored type when you do not supply Event Payload Type Schema. It is not sent on every request. Runtime body comes from the HTTP client.
Response is a static JSON body returned when no Wait-for-Response trigger (or listener) supplies a live result. It is not “what the trigger returns.” Wait for Response is a field on the Trigger, not on this form.
For a first handle you can leave both blank, or set a stub ACK:
Event Payload:
{"n": 3}(type sample only)Response:
{"ok": true}(static ACK if nothing is waiting)Response Status Code: blank → 200
Leave XML parser options false unless the body is XML.
Require Poly API Key¶
Leave Require Poly API Key as false only for a throwaway test. That means anyone who knows the URL can POST. Turn it on, or add Webhook Security Functions, before you share the URL.
Save¶
Scroll to the top and click Save.
Updating / deleting¶
After save you should see the detail page:
Click Update or Delete.
What you have now¶
You have a public URL. It does not run your code until you attach a trigger.
Next:
Webhook Security Functions — reject unwanted callers
Managing Triggers — route to a server function; set Wait for Response there
Events and Triggers — three-arg signature and injected headers