Update account

Set the default callback URL and signing secret.

PATCHhttps://api.easydata.win/v1/account
free

Sets where batch completions are delivered when a batch does not name its own callback_url, and the secret they are signed with.

The two fields are independent. Sending only webhook_url leaves the secret alone, which matters: rotating a secret every time somebody edits a URL would break every receiver already verifying against it. Omit webhook_secret on a first save and one is generated for you.

Sending webhook_secret rotates the single secret we sign with, so any callback_url destination you have used starts signing with the new value too. That is the point - one key to implement against - but it means every receiver verifying the old one has to be updated at the same time.

Send "webhook_url": "" to remove the destination entirely.

Request #

FieldTypeNotes
webhook_urlstringWhere completions go. An empty string removes the destination.
webhook_secretstringAt least 16 characters. Omit to keep the current one, or on a first save to have one generated.

Call it #

cURL
curl -X PATCH "https://api.easydata.win/v1/account" \
  -H "X-API-Key: $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"webhook_url":"https://app.example.com/hooks/enrichment"}'

Response #

JSON
{
  "data": {
    "org_id": "6b1f0e2a-3c4d-4e5f-8a9b-0c1d2e3f4a5b",
    "quota": { "unlimited": false, "limit": 25000, "used": 4182.5, "remaining": 20817.5 },
    "webhook_url": "https://app.example.com/hooks/enrichment",
    "webhook_secret": "whsec_9f2k3jd82ka0...",
    "rate_limit": {
      "requests_per_minute": 300,
      "concurrent_batches": 5,
      "sync_requests_per_minute": 60,
      "sync_concurrent_requests": 2,
      "credits_per_hour": null
    }
  },
  "meta": { "requestId": "req_8f2ka91x" }
}

Errors #

StatusTypeWhen
400invalid_requestThe body could not be accepted as sent. `error.field` names what was wrong. A field this reference does not list is one of these: an unknown key is refused rather than accepted and ignored, because a typo that is silently dropped is indistinguishable from one that worked.
401invalid_api_keyMissing, malformed, revoked or expired key. Never metered.
400invalid_requestThe URL is not public - loopback, LAN and link-local addresses are refused when you save them, and again when we dial them.

Every failure uses the same envelope, and none of them is metered - see Errors.