Verify webhook subscription Run in API Explorer

Add MCP server to your AI tool

Allow AI tools and LLMs to interact with the API documentation portal through MCP.

MCP server URL

https://docs.staging.lumetrade.com/mcp

Standard setup for AI tools providing an mcp.json file

mcp.json
{
  "Lumetrade Staging API MCP server": {
    "url": "https://docs.staging.lumetrade.com/mcp"
  }
}

Close
POST /api/v1/webhooks/subscriptions/{subscriptionId}/verify

Sends a webhook.verification challenge to the subscription targetUrl. The callback must return any 2xx response. Verification challenges use the same signed callback header contract as deliveries. Unverified subscriptions can retry this endpoint after the verification cooldown. Verified subscriptions return their current details.

Headers

  • X-API-KEY string Required

    Public API key issued from the Lumetrade API key management flow.

  • X-API-SECRET string Required

    API secret paired with the public API key.

Path parameters

  • subscriptionId string Required

    Webhook subscription id.

Responses

  • 200 application/json

    Webhook subscription verified or already verified

    Hide response attributes Show response attributes object
    • id string

      Public webhook subscription id.

    • name string

      Optional customer label.

    • targetUrl string

      Public HTTPS callback URL.

    • status string

      Subscription status. PENDING_VERIFICATION requires verify before activation. INACTIVE subscriptions receive no new deliveries. DISABLED subscriptions are not customer re-enabled in v1.

      Values are PENDING_VERIFICATION, ACTIVE, INACTIVE, or DISABLED.

    • events array[object]

      Customer-facing webhook event catalog entry.

      Hide events attributes Show events attributes object

      Customer-facing webhook event catalog entry.

      • eventType string

        Customer-facing event key used in subscription requests.

      • resourceType string

        Resource category for the event.

      • event string

        Event name within the resource category.

      • displayName string

        Human-readable event name.

      • description string

        Short description of when the event is emitted.

    • verifiedAt string(date-time)

      UTC timestamp when the callback endpoint was last verified.

    • createdAt string(date-time)

      UTC creation timestamp.

    • updatedAt string(date-time)

      UTC last update timestamp.

  • 400 application/json

    Request validation failed

    Hide response attributes Show response attributes object
    • code integer(int32)
    • message string
    • httpStatus integer(int32)
    • requestId string
    • timestamp string(date-time)
    • errors array[object]
      Hide errors attributes Show errors attributes object
      • field string
      • message string
  • 404 application/json

    Resource was not found for the authenticated API key owner

    Hide response attributes Show response attributes object
    • code integer(int32)
    • message string
    • httpStatus integer(int32)
    • requestId string
    • timestamp string(date-time)
    • errors array[object]
      Hide errors attributes Show errors attributes object
      • field string
      • message string
  • 429 application/json

    Cloudflare API rate limit exceeded

    Hide response attributes Show response attributes object
    • error string
    • message string
  • 403 application/json

    Authenticated API key is not allowed to perform this action

    Hide response attributes Show response attributes object
    • code integer(int32)
    • message string
    • httpStatus integer(int32)
    • requestId string
    • timestamp string(date-time)
    • errors array[object]
      Hide errors attributes Show errors attributes object
      • field string
      • message string
  • 401 application/json

    API key authentication failed

    Hide response attributes Show response attributes object
    • code integer(int32)
    • message string
    • httpStatus integer(int32)
    • requestId string
    • timestamp string(date-time)
    • errors array[object]
      Hide errors attributes Show errors attributes object
      • field string
      • message string
  • 500 application/json

    Unexpected server error

    Hide response attributes Show response attributes object
    • code integer(int32)
    • message string
    • httpStatus integer(int32)
    • requestId string
    • timestamp string(date-time)
    • errors array[object]
      Hide errors attributes Show errors attributes object
      • field string
      • message string
POST /api/v1/webhooks/subscriptions/{subscriptionId}/verify
curl \
 --request POST 'https://api.staging.lumetrade.com/api/v1/webhooks/subscriptions/whsub_5e737a5abaee46568bd8d530b9b3521a/verify' \
 --header "X-API-KEY: string" \
 --header "X-API-SECRET: string"
Response examples (200)
{
  "id": "whsub_5e737a5abaee46568bd8d530b9b3521a",
  "name": "Ops webhook alerts",
  "targetUrl": "https://example.com/webhooks",
  "status": "PENDING_VERIFICATION",
  "events": [
    {
      "eventType": "deposit.completed",
      "resourceType": "deposit",
      "event": "completed",
      "displayName": "Deposit completed",
      "description": "Deposit has completed."
    }
  ],
  "verifiedAt": "2026-06-12T15:03:23Z",
  "createdAt": "2026-06-12T15:01:00Z",
  "updatedAt": "2026-06-12T15:03:23Z"
}
Response examples (400)
{
  "httpStatus": 400,
  "errors": [],
  "timestamp": "2026-01-01T00:00:00Z",
  "code": 400,
  "message": "Request validation failed",
  "requestId": "req_01HY0000000000000000000000"
}
Response examples (404)
{
  "httpStatus": 404,
  "errors": [],
  "timestamp": "2026-01-01T00:00:00Z",
  "code": 404,
  "message": "Resource was not found for the authenticated API key owner",
  "requestId": "req_01HY0000000000000000000000"
}
Response examples (429)
{
  "error": "rate_limit_exceeded",
  "message": "API rate limit exceeded"
}
Response examples (403)
{
  "httpStatus": 403,
  "errors": [],
  "timestamp": "2026-01-01T00:00:00Z",
  "code": 403,
  "message": "Authenticated API key is not allowed to perform this action",
  "requestId": "req_01HY0000000000000000000000"
}
Response examples (401)
{
  "httpStatus": 401,
  "errors": [],
  "timestamp": "2026-01-01T00:00:00Z",
  "code": 401,
  "message": "API key authentication failed",
  "requestId": "req_01HY0000000000000000000000"
}
Response examples (500)
{
  "httpStatus": 500,
  "errors": [],
  "timestamp": "2026-01-01T00:00:00Z",
  "code": 500,
  "message": "Unexpected server error",
  "requestId": "req_01HY0000000000000000000000"
}