> ## Documentation Index
> Fetch the complete documentation index at: https://docs.shelfforce.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Register webhook

> Registers a new webhook endpoint to receive event notifications. Requires admin role. The `secret` for HMAC-SHA256 signature verification is returned only in this response -- store it securely.



## OpenAPI

````yaml /openapi.json post /api/v1/webhooks
openapi: 3.1.0
info:
  title: Shelfforce API
  version: 1.0.0
  description: >-
    Shelfforce turns shelf photos into structured retail data. Submit images for
    AI-powered shelf analysis, manage tasks and inventory, and retrieve
    compliance and share-of-shelf reports.


    All API requests require a Bearer token (API key with `sf_live_` prefix).
    Rate limits are enforced per tier using a fixed 60-second window.
    Idempotency is supported on POST and PATCH via the `Idempotency-Key` header
    (24h TTL).


    1 credit = 1 image analysis. Batch submissions consume 1 credit per image
    (max batch size depends on plan tier: 20-200). Tag analyses with
    `externalId` and `metadata` for B2B tracking, and use `callbackUrl` for
    per-request completion notifications.
  termsOfService: https://shelfforce.ai/terms
  contact:
    name: Shelfforce Support
    url: https://shelfforce.ai/support
    email: hey@shelfforce.ai
  license:
    name: Proprietary
    url: https://shelfforce.ai/terms
servers:
  - url: https://shelfforce.ai
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Analyses
    description: Submit images for AI shelf analysis and retrieve results.
  - name: Products
    description: Browse products detected across analyses.
  - name: Places
    description: Manage store locations tied to your organisation.
  - name: Tasks
    description: Create and manage field data-collection tasks.
  - name: Inventory
    description: Maintain a master catalogue of expected SKUs.
  - name: Reports
    description: 'Aggregated analytics: share of shelf and store performance.'
  - name: Webhooks
    description: Register endpoints to receive real-time event notifications.
  - name: Usage
    description: Check credit balance, plan details, and rate-limit status.
  - name: Orders
    description: Create and manage purchase orders with line items.
  - name: Accounts
    description: Manage brand, supplier, distributor, and partner accounts.
  - name: Alerts
    description: >-
      Read and manage system-generated alerts. Alerts are created automatically
      — no POST endpoint.
  - name: Members
    description: >-
      List, invite, update, and remove organisation members. Admin role required
      for writes.
paths:
  /api/v1/webhooks:
    post:
      tags:
        - Webhooks
      summary: Register webhook
      description: >-
        Registers a new webhook endpoint to receive event notifications.
        Requires admin role. The `secret` for HMAC-SHA256 signature verification
        is returned only in this response -- store it securely.
      operationId: createWebhook
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - url
                - events
              properties:
                url:
                  type: string
                  format: uri
                  description: HTTPS URL to receive webhook POST requests.
                  examples:
                    - https://api.example.com/webhooks/shelfforce
                events:
                  type: array
                  minItems: 1
                  items:
                    type: string
                    enum:
                      - analysis.completed
                      - analysis.failed
                      - task.created
                      - task.completed
                      - task.updated
                      - '*'
                  description: Events to subscribe to. Use `*` for all events.
                  examples:
                    - - analysis.completed
                      - analysis.failed
                description:
                  type: string
                  description: Human-readable label for the endpoint.
                  examples:
                    - Production analysis handler
              additionalProperties: false
      responses:
        '202':
          description: >-
            Webhook endpoint registered. The `secret` field is shown only in
            this response.
          headers:
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                required:
                  - data
                properties:
                  data:
                    type: object
                    required:
                      - id
                      - url
                      - events
                      - secret
                      - status
                      - createdAt
                    properties:
                      id:
                        type: string
                        examples:
                          - wh_abc123
                      url:
                        type: string
                        format: uri
                        examples:
                          - https://api.example.com/webhooks/shelfforce
                      events:
                        type: array
                        items:
                          type: string
                        examples:
                          - - analysis.completed
                            - analysis.failed
                      secret:
                        type: string
                        description: >-
                          HMAC-SHA256 signing secret. Shown only once at
                          creation time.
                        examples:
                          - whsec_a1b2c3d4e5f6g7h8i9j0
                      status:
                        type: string
                        enum:
                          - active
                          - inactive
                        examples:
                          - active
                      createdAt:
                        type: string
                        format: date-time
                        examples:
                          - '2026-02-23T10:30:00Z'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '422':
          $ref: '#/components/responses/ValidationFailed'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: false
      description: >-
        Unique key for idempotent requests. If a request with the same key was
        already processed within the last 24 hours, the cached response is
        returned with `X-Idempotent-Replayed: true`.
      schema:
        type: string
        examples:
          - idk_550e8400-e29b-41d4-a716-446655440000
  headers:
    X-RateLimit-Limit:
      description: Maximum number of requests allowed in the current 60-second window.
      schema:
        type: integer
        examples:
          - 120
    X-RateLimit-Remaining:
      description: Number of requests remaining in the current window.
      schema:
        type: integer
        examples:
          - 117
    X-RateLimit-Reset:
      description: Unix timestamp (seconds) when the current rate-limit window resets.
      schema:
        type: integer
        examples:
          - 1740300060
    X-Request-Id:
      description: Unique identifier for this request. Include in support tickets.
      schema:
        type: string
        format: uuid
        examples:
          - 550e8400-e29b-41d4-a716-446655440000
  responses:
    Unauthorized:
      description: Authentication failed. Provide a valid API key as a Bearer token.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
      content:
        application/json:
          schema:
            type: object
            required:
              - error
            properties:
              error:
                type: object
                required:
                  - code
                  - message
                properties:
                  code:
                    type: string
                    enum:
                      - AUTH_REQUIRED
                      - INVALID_API_KEY
                    examples:
                      - INVALID_API_KEY
                  message:
                    type: string
                    examples:
                      - The provided API key is invalid or has been revoked.
    Forbidden:
      description: You do not have permission to perform this action.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
      content:
        application/json:
          schema:
            type: object
            required:
              - error
            properties:
              error:
                type: object
                required:
                  - code
                  - message
                properties:
                  code:
                    type: string
                    const: FORBIDDEN
                    examples:
                      - FORBIDDEN
                  message:
                    type: string
                    examples:
                      - Admin role required to manage webhooks.
    ValidationFailed:
      description: Request body or query parameters failed validation.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
      content:
        application/json:
          schema:
            type: object
            required:
              - error
            properties:
              error:
                type: object
                required:
                  - code
                  - message
                properties:
                  code:
                    type: string
                    const: VALIDATION_FAILED
                    examples:
                      - VALIDATION_FAILED
                  message:
                    type: string
                    examples:
                      - The 'imageUrl' field must be a valid URL.
    RateLimited:
      description: Too many requests. Wait until the rate-limit window resets.
      headers:
        Retry-After:
          description: Seconds until the rate-limit window resets.
          schema:
            type: integer
            examples:
              - 12
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
      content:
        application/json:
          schema:
            type: object
            required:
              - error
            properties:
              error:
                type: object
                required:
                  - code
                  - message
                properties:
                  code:
                    type: string
                    const: RATE_LIMITED
                    examples:
                      - RATE_LIMITED
                  message:
                    type: string
                    examples:
                      - Rate limit exceeded. Retry after 12 seconds.
    InternalError:
      description: An unexpected server error occurred.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
      content:
        application/json:
          schema:
            type: object
            required:
              - error
            properties:
              error:
                type: object
                required:
                  - code
                  - message
                properties:
                  code:
                    type: string
                    const: INTERNAL_ERROR
                    examples:
                      - INTERNAL_ERROR
                  message:
                    type: string
                    examples:
                      - >-
                        An unexpected error occurred. Please try again or
                        contact support with request ID.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: >-
        API key with `sf_live_` prefix. Pass as `Authorization: Bearer
        sf_live_...`

````