> ## Documentation Index
> Fetch the complete documentation index at: https://developers.vizito.eu/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring the webhook

> Creates the webhook or replaces the existing one. Saving also clears the
consecutive-failure counter, so this is how you re-enable a webhook that
was switched off.

Events carry `eventName` and `companyId` plus the ids of what changed:
`visitor_signed_in`, `visitor_signed_out`, `visitor_updated`,
`visitor_screening_approved`, `visitor_screening_rejected`,
`registered_visitor_created`, `registered_visitor_updated`,
`registered_visitor_deleted`, `registered_visitor_preregistered`,
`device_added`, `device_online`, `device_offline`, `device_deleted`,
`company_updated`.




## OpenAPI

````yaml https://vizito.eu/openapi.yaml post /companies/{company_id}/webhooks
openapi: 3.1.0
info:
  title: Vizito API
  version: 1.0.0
  description: |
    Read and write your Vizito visitor data over HTTPS.

    Every endpoint takes and returns JSON, and is authenticated with an API key
    created by a global admin on the Integrations page of the Backoffice.

    Almost every endpoint names a **location** — `company_id` in the API. Your
    key is pinned to a set of locations; naming one outside that set is refused
    with `403`. Start at `GET /companiesList`, the one endpoint that needs no
    location id.
  contact:
    name: Vizito support
    email: support@vizito.eu
    url: https://vizito.eu
  termsOfService: https://vizito.eu/terms
servers:
  - url: https://api.vizito.eu/api
    description: Production
security:
  - apiKey: []
tags:
  - name: Locations
    description: The locations your credential covers, and their configuration.
  - name: Visitors
    description: The visits themselves — one visitor is one visit, not a person.
  - name: Registered visitors
    description: Expected visitors — pre-register, invite, and sign in on arrival.
  - name: Hosts
    description: The people who can be visited.
  - name: Visit types
    description: The sign-in flows, and the questions they ask.
  - name: Entry points
    description: The doors and desks within a location.
  - name: Agreements
    description: The documents visitors sign, and the signed PDFs that come out.
  - name: Devices
    description: The kiosks at a location.
  - name: Reporting
    description: Counters, graphs and exports.
  - name: Webhooks
    description: The endpoint Vizito calls when something happens.
paths:
  /companies/{company_id}/webhooks:
    post:
      tags:
        - Webhooks
      summary: Configuring the webhook
      description: |
        Creates the webhook or replaces the existing one. Saving also clears the
        consecutive-failure counter, so this is how you re-enable a webhook that
        was switched off.

        Events carry `eventName` and `companyId` plus the ids of what changed:
        `visitor_signed_in`, `visitor_signed_out`, `visitor_updated`,
        `visitor_screening_approved`, `visitor_screening_rejected`,
        `registered_visitor_created`, `registered_visitor_updated`,
        `registered_visitor_deleted`, `registered_visitor_preregistered`,
        `device_added`, `device_online`, `device_offline`, `device_deleted`,
        `company_updated`.
      operationId: configureWebhook
      parameters:
        - $ref: '#/components/parameters/companyId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - url
                - http_method
              properties:
                url:
                  type: string
                  format: uri
                  description: A valid, publicly reachable URL.
                http_method:
                  type: string
                  enum:
                    - POST
                    - PUT
                    - PATCH
                    - GET
                  description: >-
                    With `GET` the event is sent as query parameters instead of
                    a body.
                enabled:
                  type: boolean
                  default: false
                auth_username:
                  type: string
                  description: Sent as HTTP Basic credentials with `auth_password`.
                auth_password:
                  type: string
      responses:
        '200':
          description: The webhook was configured.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    example: Webhook configured successfully
                  webhook_id:
                    $ref: '#/components/schemas/ObjectId'
        '400':
          description: Invalid HTTP method, or a missing or unparseable URL.
        '403':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
components:
  parameters:
    companyId:
      name: company_id
      in: path
      required: true
      description: The location.
      schema:
        $ref: '#/components/schemas/ObjectId'
  schemas:
    ObjectId:
      type: string
      pattern: ^[0-9a-fA-F]{24}$
      description: A 24-character hexadecimal id.
      example: 5f2a1b9c4d3e2f0011223344
    Message:
      type: object
      properties:
        message:
          type: string
  responses:
    Unauthorized:
      description: |
        The credential was refused, or the endpoint is off limits to API keys.
        Every refusal answers identically — see the Authentication page.
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
                example: Invalid API key
    NotFound:
      description: No such object, or a location your credential does not cover.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Message'
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >
        An API key issued in the Backoffice, sent as `Authorization: Bearer
        vzk_<key id>_<secret>`.

        A Microsoft Entra ID access token obtained with the client credentials

        grant is accepted on the same header. The same value is also accepted in

        an `X-API-Key` header.

````

## Related topics

- [Webhooks](/documentation/webhooks.md)
- [Fetching the webhook](/api-reference/webhooks/fetching-the-webhook.md)
- [Introduction](/index.md)
- [Listing recent visits](/api-reference/visitors/listing-recent-visits.md)
- [Listing devices](/api-reference/devices/listing-devices.md)
