> ## Documentation Index
> Fetch the complete documentation index at: https://docs.guidinghand.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Set the webhook endpoint

> Only the fields you send change: without `url` the endpoint stays, without `events` the filter stays (so `{ "rotate_secret": true }` alone just makes a new secret). Send `{ "url": null }` to remove the endpoint. The signing secret is returned when it is first made (or with `rotate_secret`), never again.



## OpenAPI

````yaml /api-reference/openapi.json put /v1/webhook
openapi: 3.1.0
info:
  title: GuidingHand API
  version: 1.0.0
  description: >-
    Create sessions (an invite link with a code for the person at the computer),
    run tasks on their computer with one of your agents, follow them, answer
    their questions and approvals, and fetch history and recordings.
servers:
  - url: https://guidinghand.ai
    description: Production
  - url: https://dev.guidinghand.ai
    description: Development (Stripe test mode)
security:
  - bearerAuth: []
tags:
  - name: Agents
  - name: Sessions
  - name: Tasks
  - name: Webhooks
paths:
  /v1/webhook:
    put:
      tags:
        - Webhooks
      summary: Set the webhook endpoint
      description: >-
        Only the fields you send change: without `url` the endpoint stays,
        without `events` the filter stays (so `{ "rotate_secret": true }` alone
        just makes a new secret). Send `{ "url": null }` to remove the endpoint.
        The signing secret is returned when it is first made (or with
        `rotate_secret`), never again.
      operationId: setWebhook
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                url:
                  type:
                    - string
                    - 'null'
                  format: uri
                  example: https://example.com/guidinghand
                  description: >-
                    A public https URL. Required the first time; null removes
                    the endpoint.
                events:
                  type: array
                  items:
                    $ref: '#/components/schemas/WebhookEventType'
                  description: >-
                    Only these events; an empty list for all. Unknown types are
                    a 400.
                rotate_secret:
                  type: boolean
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Webhook'
        '400':
          $ref: '#/components/responses/E400'
        '401':
          $ref: '#/components/responses/E401'
        '403':
          $ref: '#/components/responses/E403'
components:
  schemas:
    WebhookEventType:
      type: string
      enum:
        - session.connected
        - session.disconnected
        - task.started
        - task.waiting_for_user
        - task.question_answered
        - task.waiting_for_approval
        - task.approval_decided
        - task.completed
        - task.failed
        - task.stopped
    Webhook:
      type: object
      properties:
        object:
          const: webhook
        url:
          type:
            - string
            - 'null'
        events:
          type: array
          items:
            $ref: '#/components/schemas/WebhookEventType'
        has_secret:
          type: boolean
        secret:
          type: string
          description: Only when it was just made.
        event_types:
          type: array
          items:
            $ref: '#/components/schemas/WebhookEventType'
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - type
            - message
          properties:
            type:
              type: string
              enum:
                - invalid_request
                - authentication
                - payment_required
                - permission
                - not_found
                - conflict
                - rate_limit
                - server_error
            message:
              type: string
            code:
              type: string
              description: >-
                Why an answer or decision was refused (on `/respond`):
                `already_answered` (someone answered or decided first: see
                `answered_by`) or `not_pending` (that question or approval isn’t
                open any more). The GuidingHand app hears two more, which the
                API never returns: `customer_answers_off` and
                `customer_approvals_off` (the agent keeps its questions or
                approvals for your team).
            answered_by:
              type: string
              enum:
                - customer
                - operator
              description: >-
                With `already_answered`: who answered or decided first
                (`customer`: the person at the computer).
  responses:
    E400:
      description: The request is invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    E401:
      description: Missing or invalid API key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    E403:
      description: Your role can’t do this.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: An org API key (`gh_live_…`) from Settings → API keys in the console.

````