Skip to main content
POST
Register a webhook endpoint

Authorizations

Authorization
string
header
required

Partner API key: Authorization: Bearer whk_…. Keys are issued by the Whistle team (email tommy@huddleup-sports.com), shown once at issuance, and bound to your source namespace — they access only your leagues (plus explicit grants) and your webhook endpoints. Any auth failure returns 401 {"error":"unauthorized"}; the API never returns 403 — out-of-scope resources answer 404 exactly like nonexistent ones.

Body

application/json
url
string<uri>
required

HTTPS only.

events
enum<string>[]

Empty/omitted = all events.

Available options:
game.created,
game.updated,
game.cancelled,
game.completed,
position.claimed,
position.released,
payment.paid,
payment.failed,
official.joined,
official.approved,
official.removed,
official.no_show
source
string

Derived from your key — omit, or echo your key's source; any other value returns 400 source_mismatch.

Maximum string length: 40

Response

Created endpoint including the once-only secret

data
object
Last modified on July 13, 2026