curl --request POST \
--url https://app.base44.com/api/agents/{agent_id}/webhooks \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"target_url": "https://example.com/hooks/agent",
"events": [
"message.completed"
],
"description": "CRM sync",
"generate_secret": true
}
'import requests
url = "https://app.base44.com/api/agents/{agent_id}/webhooks"
payload = {
"target_url": "https://example.com/hooks/agent",
"events": ["message.completed"],
"description": "CRM sync",
"generate_secret": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
target_url: 'https://example.com/hooks/agent',
events: ['message.completed'],
description: 'CRM sync',
generate_secret: true
})
};
fetch('https://app.base44.com/api/agents/{agent_id}/webhooks', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/agents/{agent_id}/webhooks",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'target_url' => 'https://example.com/hooks/agent',
'events' => [
'message.completed'
],
'description' => 'CRM sync',
'generate_secret' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/agents/{agent_id}/webhooks"
payload := strings.NewReader("{\n \"target_url\": \"https://example.com/hooks/agent\",\n \"events\": [\n \"message.completed\"\n ],\n \"description\": \"CRM sync\",\n \"generate_secret\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.base44.com/api/agents/{agent_id}/webhooks")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"target_url\": \"https://example.com/hooks/agent\",\n \"events\": [\n \"message.completed\"\n ],\n \"description\": \"CRM sync\",\n \"generate_secret\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/agents/{agent_id}/webhooks")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"target_url\": \"https://example.com/hooks/agent\",\n \"events\": [\n \"message.completed\"\n ],\n \"description\": \"CRM sync\",\n \"generate_secret\": true\n}"
response = http.request(request)
puts response.read_body{
"id": "68a1d0f4f0b9d3002e7a5c52",
"target_url": "https://example.com/hooks/agent",
"events": [
"message.completed"
],
"description": "CRM sync",
"has_secret": true,
"last_trigger_time": "2026-08-02T14:30:00Z",
"last_error": {
"message": "Non-2xx response: 500",
"attempted_at": "2026-08-02T14:30:00+00:00",
"status_code": 500,
"response_body": "Internal Server Error",
"error_type": "ConnectTimeout"
},
"consecutive_failures": 0,
"disabled_at": "2026-08-03T08:00:00Z",
"created_date": "2026-08-01T09:15:00Z",
"updated_date": "2026-08-02T14:30:00Z",
"secret": "Rk3x9QeN0vZ8bL2mT6yH4cJ1wP7sD5fG0aX9kV3uE8o"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}Create Superagent webhook
Subscribes a URL to a Superagent’s conversation events.
events takes one or more of message.created, which fires when a message is added to a conversation, and message.completed, which fires when the agent finishes a reply. target_url has to be a public HTTPS URL. An agent can have up to 5 webhooks, and each call adds one, so retrying a create that may have succeeded can add a duplicate. Check List Superagent webhooks first.
Base44 sends each event once and doesn’t retry a failed delivery. A failure is recorded in last_error and counts toward consecutive_failures.
Set generate_secret to true to sign deliveries. The response then carries secret, the only time Base44 shows it.
curl --request POST \
--url https://app.base44.com/api/agents/{agent_id}/webhooks \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"target_url": "https://example.com/hooks/agent",
"events": [
"message.completed"
],
"description": "CRM sync",
"generate_secret": true
}
'import requests
url = "https://app.base44.com/api/agents/{agent_id}/webhooks"
payload = {
"target_url": "https://example.com/hooks/agent",
"events": ["message.completed"],
"description": "CRM sync",
"generate_secret": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
target_url: 'https://example.com/hooks/agent',
events: ['message.completed'],
description: 'CRM sync',
generate_secret: true
})
};
fetch('https://app.base44.com/api/agents/{agent_id}/webhooks', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/agents/{agent_id}/webhooks",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'target_url' => 'https://example.com/hooks/agent',
'events' => [
'message.completed'
],
'description' => 'CRM sync',
'generate_secret' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/agents/{agent_id}/webhooks"
payload := strings.NewReader("{\n \"target_url\": \"https://example.com/hooks/agent\",\n \"events\": [\n \"message.completed\"\n ],\n \"description\": \"CRM sync\",\n \"generate_secret\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.base44.com/api/agents/{agent_id}/webhooks")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"target_url\": \"https://example.com/hooks/agent\",\n \"events\": [\n \"message.completed\"\n ],\n \"description\": \"CRM sync\",\n \"generate_secret\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/agents/{agent_id}/webhooks")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"target_url\": \"https://example.com/hooks/agent\",\n \"events\": [\n \"message.completed\"\n ],\n \"description\": \"CRM sync\",\n \"generate_secret\": true\n}"
response = http.request(request)
puts response.read_body{
"id": "68a1d0f4f0b9d3002e7a5c52",
"target_url": "https://example.com/hooks/agent",
"events": [
"message.completed"
],
"description": "CRM sync",
"has_secret": true,
"last_trigger_time": "2026-08-02T14:30:00Z",
"last_error": {
"message": "Non-2xx response: 500",
"attempted_at": "2026-08-02T14:30:00+00:00",
"status_code": 500,
"response_body": "Internal Server Error",
"error_type": "ConnectTimeout"
},
"consecutive_failures": 0,
"disabled_at": "2026-08-03T08:00:00Z",
"created_date": "2026-08-01T09:15:00Z",
"updated_date": "2026-08-02T14:30:00Z",
"secret": "Rk3x9QeN0vZ8bL2mT6yH4cJ1wP7sD5fG0aX9kV3uE8o"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}Authorizations
Personal access token, sent as Authorization: Bearer <token>.
Path Parameters
ID of the Superagent. It's the agent's app ID, shown in the agent's developer settings.
Body
Public HTTPS URL that receives the events.
"https://example.com/hooks/agent"
Events to receive. One or more of message.created and message.completed.
["message.completed"]
Your label for the webhook.
"CRM sync"
true makes Base44 generate an HMAC-SHA256 signing secret and return it once in the response. Deliveries are signed with an X-Base44-Signature header only when the webhook has a secret.
true
Response
The new webhook.
A webhook subscription, with its signing secret when one was just generated.
ID of the webhook.
"68a1d0f4f0b9d3002e7a5c52"
HTTPS URL Base44 sends the events to.
"https://example.com/hooks/agent"
Events the webhook receives. message.created fires when a message is added to a conversation, and message.completed when the agent finishes a reply.
message.created, message.completed ["message.completed"]
Your label for the webhook, or null when it has none.
"CRM sync"
Whether deliveries are signed. When true, each delivery carries an X-Base44-Signature header, an HMAC-SHA256 of the body.
true
Time of the last delivery attempt, successful or not, as a UTC timestamp in ISO 8601 format, or null before the first one.
"2026-08-02T14:30:00Z"
What went wrong on the last failed delivery, or null when the last delivery succeeded or none has failed.
Show child attributes
Show child attributes
Deliveries that failed in a row. After 20, Base44 turns the webhook off and sets disabled_at.
0
Time the webhook was turned off, as a UTC timestamp in ISO 8601 format, or null while it's on. Turn it back on with enabled: true in Update Superagent webhook.
"2026-08-03T08:00:00Z"
Time the webhook was created, as a UTC timestamp in ISO 8601 format.
"2026-08-01T09:15:00Z"
Time the webhook last changed, as a UTC timestamp in ISO 8601 format.
"2026-08-02T14:30:00Z"
The signing secret, returned only in the response that generates it. Store it, because no other response shows it again.
"Rk3x9QeN0vZ8bL2mT6yH4cJ1wP7sD5fG0aX9kV3uE8o"
Was this page helpful?