SIEM and Shared Signals
Change a webhook
PATCH
/api/w/:wid/webhooks/:idOwners and admins. Any of url, events and format; the secret stays. A kind the ledger never writes is refused with 400 invalid_events and the closest real one (“did you mean agent_freeze?”).
#Authentication
Session cookie
A signed-in person: the console's session cookie. Every state-changing request also carries the header x-immiscible-csrf: 1, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.
#Path parameters
widstringrequired
Workspace id
idstringrequired
Webhook id