curl -X POST "https://api.fitsociety.io/public/v1/webhooks" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: webhook-create-crm-sync-20260714" \
-H "Content-Type: application/json" \
-d '{"name":"CRM sync","url":"https://example.com/fitsociety/webhooks","events":["client.created","client.updated"]}'const options = {
method: 'POST',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: 'CRM sync',
url: 'https://example.com/fitsociety/webhooks',
events: ['client.created', 'client.updated']
})
};
fetch('https://api.fitsociety.io/public/v1/webhooks', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/webhooks"
payload = {
"name": "CRM sync",
"url": "https://example.com/fitsociety/webhooks",
"events": ["client.created", "client.updated"]
}
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"data": {
"subscription": {
"id": "66f7b8b1e13c8d25f4d3d90a",
"name": "CRM sync",
"status": "active",
"events": [
"client.created",
"client.updated"
],
"target": {
"type": "url",
"url": "https://example.com/fitsociety/webhooks"
},
"secret": {
"prefix": "whsec_12",
"last4": "9abc",
"rotatedAt": "2026-07-14T09:30:00.000Z"
},
"lastDeliveryAt": "2026-07-14T10:00:00.000Z",
"lastSuccessAt": "2026-07-14T10:00:00.000Z",
"lastFailureAt": "2026-07-14T10:00:00.000Z",
"createdAt": "2026-07-14T10:00:00.000Z",
"updatedAt": "2026-07-14T10:00:00.000Z",
"signingSecret": "whsec_0123456789abcdefghijklmnopqrstuvwxyz"
}
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Create a webhook subscription
Requires webhooks:write. Creates an outbound webhook subscription for a public HTTPS target URL. The response includes signingSecret exactly once; store it securely because later reads only expose secret metadata.
curl -X POST "https://api.fitsociety.io/public/v1/webhooks" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: webhook-create-crm-sync-20260714" \
-H "Content-Type: application/json" \
-d '{"name":"CRM sync","url":"https://example.com/fitsociety/webhooks","events":["client.created","client.updated"]}'const options = {
method: 'POST',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: 'CRM sync',
url: 'https://example.com/fitsociety/webhooks',
events: ['client.created', 'client.updated']
})
};
fetch('https://api.fitsociety.io/public/v1/webhooks', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/webhooks"
payload = {
"name": "CRM sync",
"url": "https://example.com/fitsociety/webhooks",
"events": ["client.created", "client.updated"]
}
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"data": {
"subscription": {
"id": "66f7b8b1e13c8d25f4d3d90a",
"name": "CRM sync",
"status": "active",
"events": [
"client.created",
"client.updated"
],
"target": {
"type": "url",
"url": "https://example.com/fitsociety/webhooks"
},
"secret": {
"prefix": "whsec_12",
"last4": "9abc",
"rotatedAt": "2026-07-14T09:30:00.000Z"
},
"lastDeliveryAt": "2026-07-14T10:00:00.000Z",
"lastSuccessAt": "2026-07-14T10:00:00.000Z",
"lastFailureAt": "2026-07-14T10:00:00.000Z",
"createdAt": "2026-07-14T10:00:00.000Z",
"updatedAt": "2026-07-14T10:00:00.000Z",
"signingSecret": "whsec_0123456789abcdefghijklmnopqrstuvwxyz"
}
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.
Headers
Required for Public API write requests. Reusing the same key with the same method, path, and body replays the stored successful response; reusing it with a different request returns 409 idempotency.conflict.
1 - 200"booking-create-20260714-001"
Body
120"CRM sync"
Public HTTPS URL that receives outbound FITsociety webhook deliveries.
"https://example.com/fitsociety/webhooks"
1subscription.test, client.created, client.updated, client.archived, client.invited, client.portal_access.changed, client.relationship.approved, client.relationship.rejected, client.note.created, client.note.updated, client.note.deleted, conversation.created, conversation.updated, conversation.participant.added, conversation.participant.removed, conversation.message.created, conversation.message.updated, conversation.message.deleted, booking.created, booking.updated, booking.cancelled, booking_request.created, booking_request.approved, booking_request.rejected, recurring_booking.changed, calendar_task.created, calendar_task.updated, calendar_task.cancelled, invoice.created, invoice.sent, invoice.overdue, invoice.cancelled, invoice.paid, payment.succeeded, payment.failed, payment.request.created, payment.request.cancelled, chargeback.created, subscription.changed, subscription.cancelled, client_product.assigned, client_product.revoked, credit.assigned, credit.adjusted, credit.revoked, membership.assigned, form.assigned, form.submitted, intake.submitted, checkup.assigned, checkup.submitted, measurement.created, measurement.updated, progress_photo.created, goal.updated, habit_entry.created, document.linked, document.updated, document.archived ["client.created", "client.updated"]