> ## Documentation Index
> Fetch the complete documentation index at: https://www.worldmonitor.app/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# RegisterWebhook

> RegisterWebhook subscribes a callback URL to chokepoint disruption alerts.
 Returns the subscriberId and the raw HMAC secret — the secret is never
 returned again except via rotate-secret. PRO-gated. Requires an active Pro subscription.



## OpenAPI

````yaml /api/worldmonitor.openapi.yaml post /api/v2/shipping/webhooks
openapi: 3.1.0
info:
  title: WorldMonitor API
  description: >-
    Unified OpenAPI bundle spanning all WorldMonitor services. Versioning and
    deprecation policy: https://www.worldmonitor.app/docs/api-versioning
  contact:
    name: WorldMonitor
    email: support@worldmonitor.app
  version: 1.0.0
servers:
  - url: https://api.worldmonitor.app
security:
  - WorldMonitorKey: []
  - ApiKeyHeader: []
paths:
  /api/v2/shipping/webhooks:
    post:
      tags:
        - ShippingV2Service
      summary: RegisterWebhook
      description: >-
        RegisterWebhook subscribes a callback URL to chokepoint disruption
        alerts.
         Returns the subscriberId and the raw HMAC secret — the secret is never
         returned again except via rotate-secret. PRO-gated. Requires an active Pro subscription.
      operationId: RegisterWebhook
      parameters:
        - name: Idempotency-Key
          in: header
          description: >-
            Optional client-generated idempotency key. Retrying a POST with the
            same key and an identical request body replays the original response
            (only the status, body, and Content-Type are reproduced) instead of
            re-executing; reusing the key with a different body is rejected with
            422. For mutations this avoids duplicating the side effect, while
            for batch-read POSTs it replays a cached snapshot that can be up to
            24 hours stale. Keys are scoped per authenticated caller (falling
            back to the source IP for unauthenticated endpoints) and retained
            for 24 hours.
          required: false
          example: 4f8b9c2e-1a3d-4b6f-8e0a-2c5d7f9b1e34
          schema:
            type: string
            minLength: 1
            maxLength: 255
            pattern: ^[\x21-\x7E]{1,255}$
      requestBody:
        content:
          application/json:
            example:
              alertThreshold: 1
              callbackUrl: https://example.com/worldmonitor-webhook
              chokepointIds:
                - suez
            schema:
              $ref: >-
                #/components/schemas/worldmonitor_shipping_v2_RegisterWebhookRequest
        required: true
      responses:
        '200':
          description: Successful response
          headers:
            Idempotency-Key:
              schema:
                type: string
              description: >-
                The idempotency key echoed from the request. Present only when
                the client opted into idempotency.
            Idempotent-Replayed:
              schema:
                type: boolean
              description: >-
                true when this response was replayed from an earlier request
                with the same key, false on the first (original) request.
                Present only when the client opted into idempotency.
          content:
            application/json:
              example:
                secret: example
                subscriberId: example-id
              schema:
                $ref: >-
                  #/components/schemas/worldmonitor_shipping_v2_RegisterWebhookResponse
        '400':
          description: >-
            Validation error, invalid Idempotency-Key header, or malformed JSON
            request body
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/ValidationError'
                  - type: object
                    required:
                      - error
                      - message
                    properties:
                      error:
                        type: string
                      message:
                        type: string
                  - $ref: '#/components/schemas/InvalidRequestBodyError'
        '401':
          description: Missing or invalid API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedError'
        '403':
          description: Pro subscription required.
          headers:
            X-Billing-Verification:
              description: >-
                Present when the 403 is a billing-provider-confirmed
                subscription lapse (value subscription_lapsed, matching the body
                `code`).
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ForbiddenError'
        '409':
          description: A request with this Idempotency-Key is still being processed
          headers:
            Idempotency-Key:
              schema:
                type: string
              description: The idempotency key supplied by the client.
            Retry-After:
              schema:
                type: string
              description: Seconds to wait before retrying the in-flight request.
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                  - message
                properties:
                  error:
                    type: string
                  message:
                    type: string
        '422':
          description: The Idempotency-Key was already used with a different request body
          headers:
            Idempotency-Key:
              schema:
                type: string
              description: The idempotency key supplied by the client.
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                  - message
                properties:
                  error:
                    type: string
                  message:
                    type: string
        '429':
          description: Rate limit exceeded.
          headers:
            X-RateLimit-Limit:
              description: Maximum requests allowed in the active rate-limit window.
              schema:
                type: string
            X-RateLimit-Remaining:
              description: Requests remaining in the active rate-limit window.
              schema:
                type: string
            X-RateLimit-Reset:
              description: >-
                Unix epoch milliseconds when the active rate-limit window
                resets.
              schema:
                type: string
            Retry-After:
              description: Seconds to wait before retrying the request.
              schema:
                type: string
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/Error'
                  - $ref: '#/components/schemas/RateLimitError'
        '503':
          description: >-
            Service unavailable. Billing-verification responses include code and
            X-Billing-Verification; other gateway infrastructure failures use
            the generic GatewayError shape.
          headers:
            Retry-After:
              description: Seconds to wait before retrying (1-60).
              schema:
                type: string
            X-Billing-Verification:
              description: >-
                Billing-verification state that produced this response (matches
                the body `code`).
              schema:
                type: string
            X-Validation-Mode:
              description: >-
                Present with value degraded when user API-key validation is
                temporarily unavailable.
              schema:
                type: string
            X-RateLimit-Mode:
              description: >-
                Present with value degraded when a fail-closed rate-limit
                dependency is unavailable.
              schema:
                type: string
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/BillingVerificationError'
                  - $ref: '#/components/schemas/GatewayError'
        default:
          description: Gateway or handler error response.
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/Error'
                  - $ref: '#/components/schemas/GatewayError'
      security:
        - WorldMonitorKey: []
        - ApiKeyHeader: []
        - BearerAuth: []
components:
  schemas:
    worldmonitor_shipping_v2_RegisterWebhookRequest:
      type: object
      properties:
        callbackUrl:
          type: string
          maxLength: 2048
          minLength: 8
          description: >-
            HTTPS callback URL. Must not resolve to a private/loopback address
            at
             registration time (SSRF guard). The delivery worker re-validates the
             resolved IP before each send to mitigate DNS rebinding.
        chokepointIds:
          type: array
          items:
            type: string
            description: >-
              Zero or more chokepoint IDs to subscribe to. Empty list subscribes
              to
               the entire CHOKEPOINT_REGISTRY. Unknown IDs fail with 400.
        alertThreshold:
          type: integer
          maximum: 100
          minimum: 0
          format: int32
          description: |-
            Disruption-score threshold for delivery, 0-100. Default 50.
             proto3 `optional` so the handler can distinguish "partner explicitly sent
             0 (deliver every alert)" from "partner omitted the field (apply default
             50)". Without `optional`, both serialise to the proto3 scalar default of
             0 and the handler can't tell them apart — flagged in #3242 review.
      required:
        - callbackUrl
      description: |-
        RegisterWebhookRequest creates a new chokepoint-disruption webhook
         subscription. Wire shape is byte-compatible with the pre-migration
         legacy POST body.
    worldmonitor_shipping_v2_RegisterWebhookResponse:
      type: object
      properties:
        subscriberId:
          type: string
          description: '`wh_` prefix + 24 lowercase hex chars (12 random bytes).'
        secret:
          type: string
          description: >-
            Raw 64-char lowercase hex secret (32 random bytes). No `whsec_`
            prefix.
      description: >-
        RegisterWebhookResponse wire shape preserved exactly — partners persist
        the
         `secret` because the server never returns it again except via rotate-secret.
    ValidationError:
      type: object
      properties:
        violations:
          type: array
          items:
            $ref: '#/components/schemas/FieldViolation'
          description: List of validation violations
      required:
        - violations
      description: >-
        ValidationError is returned when request validation fails. It contains a
        list of field violations describing what went wrong.
    InvalidRequestBodyError:
      type: object
      description: Returned when a JSON POST request body is empty or malformed.
      properties:
        message:
          type: string
          description: Invalid request body
      required:
        - message
    UnauthorizedError:
      type: object
      properties:
        error:
          type: string
          description: Human-readable error message.
      required:
        - error
      description: >-
        Returned when the API key is missing, malformed, or lacks current API
        access.
    ForbiddenError:
      type: object
      properties:
        error:
          type: string
          description: Human-readable entitlement failure reason.
        code:
          type: string
          enum:
            - subscription_lapsed
          description: >-
            Machine-readable denial code, present when the 403 is a
            billing-provider-confirmed subscription lapse (mirrored in the
            X-Billing-Verification response header).
        requiredTier:
          type: integer
          format: int32
          description: Minimum entitlement tier required for this endpoint.
        currentTier:
          type: integer
          format: int32
          description: Caller entitlement tier when known.
        planKey:
          type: string
          description: Caller plan key when known.
      required:
        - error
      description: >-
        Returned when a PRO-gated endpoint denies access because the caller has
        no resolved authenticated user, entitlements cannot be verified, or the
        caller lacks the required entitlement tier.
    Error:
      type: object
      properties:
        message:
          type: string
          description: Error message (e.g., 'user not found', 'database connection failed')
      description: >-
        Error is returned when a handler encounters an error. It contains a
        simple error message that the developer can customize.
    RateLimitError:
      type: object
      description: Returned when a gateway or handler rate limit rejects the request.
      properties:
        error:
          type: string
          description: Human-readable rate-limit failure reason.
      required:
        - error
    BillingVerificationError:
      type: object
      description: >-
        Returned with HTTP 503 when paid access cannot be confirmed right now:
        the billing provider is re-verifying a recently expired subscription, or
        the entitlement backend is unreachable. Retryable — honor Retry-After.
      properties:
        error:
          type: string
          description: Human-readable billing-verification failure reason.
        code:
          type: string
          enum:
            - renewal_verification_pending
            - renewal_verification_failed
            - entitlement_verification_unavailable
          description: >-
            Machine-readable billing-verification state, mirrored in the
            X-Billing-Verification response header.
        requiredTier:
          type: integer
          format: int32
          description: >-
            Minimum entitlement tier required for this endpoint, when the denial
            came from a tier gate.
      required:
        - error
        - code
    GatewayError:
      type: object
      description: >-
        Returned by gateway infrastructure errors before an RPC handler runs,
        such as origin, routing, method, authentication, or quota checks.
      properties:
        error:
          oneOf:
            - type: string
            - type: object
              additionalProperties: true
          description: Gateway error reason or structured gateway failure details.
      required:
        - error
    FieldViolation:
      type: object
      properties:
        field:
          type: string
          description: >-
            The field path that failed validation (e.g., 'user.email' for nested
            fields). For header validation, this will be the header name (e.g.,
            'X-API-Key')
        description:
          type: string
          description: >-
            Human-readable description of the validation violation (e.g., 'must
            be a valid email address', 'required field missing')
      required:
        - field
        - description
      description: FieldViolation describes a single validation error for a specific field.
  securitySchemes:
    WorldMonitorKey:
      type: apiKey
      in: header
      name: X-WorldMonitor-Key
      description: User-issued WorldMonitor API key.
    ApiKeyHeader:
      type: apiKey
      in: header
      name: X-Api-Key
      description: Alias header for the WorldMonitor API key (X-WorldMonitor-Key).
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        Bearer token: a Clerk-issued JWT for browser session flows, passed as
        Authorization: Bearer <token>.

````