# Activate a webhook

`POST https://api.versionseven.ai/v1/campaigns/{campaign_id}/webhook/activate`

> **Warning:** This endpoint is deprecated but still works. Use [Create a webhook](https://docs.versionseven.ai/api-reference/campaigns/create-webhook) (`POST /v1/campaigns/{campaign_id}/webhooks`) instead.

Registers a webhook URL that will receive events when leads respond to campaign outreach. Multiple webhooks can be registered per campaign, and all active webhooks will receive events simultaneously.

- Required scope: `campaigns:write`

## Request

**cURL**

```bash
curl -X POST "https://api.versionseven.ai/v1/campaigns/550e8400-e29b-41d4-a716-446655440000/webhook/activate" \
  -H "Authorization: Bearer $VICTORIA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "webhook_url": "https://api.example.com/webhooks/victoria"
}'
```

**Node.js**

```javascript
const response = await fetch("https://api.versionseven.ai/v1/campaigns/550e8400-e29b-41d4-a716-446655440000/webhook/activate", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.VICTORIA_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "webhook_url": "https://api.example.com/webhooks/victoria"
  }),
});

const data = await response.json();
```

**Python**

```python
import os

import requests

response = requests.post(
    "https://api.versionseven.ai/v1/campaigns/550e8400-e29b-41d4-a716-446655440000/webhook/activate",
    headers={
        "Authorization": f"Bearer {os.environ['VICTORIA_API_KEY']}",
    },
    json={
        "webhook_url": "https://api.example.com/webhooks/victoria",
    },
)
data = response.json()
```

## Headers

- `Authorization` (string, required): `Bearer` followed by a space and your API key, for example `Bearer vk_…`.

## Path parameters

- `campaign_id` (string · uuid, required): ID of the campaign.

## Request body

- `webhook_url` (string, required, at most 2,000 characters, example `"https://api.example.com/webhooks/victoria"`): URL to receive webhook events
- `replace` (boolean, optional, default `false`): A campaign has one response webhook. When a different URL already holds it, the request is refused with WEBHOOK\_SLOT\_TAKEN unless this is true, in which case that webhook is repointed at webhook\_url and the previous receiver stops getting this campaign's responses.
- `secret` (string or null, optional, at least 16 characters, at most 2,000 characters): Caller-supplied HMAC signing secret so the receiver holds the same key; generated server-side when omitted (and then unrecoverable by the receiver)

## Response

### `200`

```json
{
  "webhook_id": "3a94d596-645d-47ff-a032-c70b299fc8f3",
  "created": true,
  "message": "Webhook activated successfully",
  "replaced": true,
  "secret": "string",
  "success": true
}
```

- `webhook_id` (string, required): ID of the webhook record
- `created` (boolean or null, optional): True when a new webhook was created, false when an existing disabled one was re-enabled
- `message` (string, optional, default `"Webhook activated successfully"`)
- `replaced` (boolean or null, optional): True when an existing webhook for a different URL was repointed (replace=true)
- `secret` (string or null, optional): Present only when the signing secret was generated server-side, and only in this response: store it now, it cannot be retrieved again. Absent when you supplied your own.
- `success` (boolean, optional, default `true`)

## Errors

Errors share one JSON body: `success`, `error`, `message`, optional `details`, and `request_id`. For example:

```json
{
  "success": false,
  "error": "UNAUTHORIZED",
  "message": "Invalid or inactive API key",
  "request_id": "734d11a1-54d4-414c-9e8d-4e1ada977db4"
}
```

| Status | Code | Meaning |
| --- | --- | --- |
| 400 | `VALIDATION_ERROR` | The request didn't match the endpoint's schema: a missing or malformed field, a bad query parameter, or a value out of range. `details.errors` lists each failing field with its `field`, `message` and `type`. |
| 400 | `INVALID_WEBHOOK_URL` | The webhook URL must use `https` and resolve to a public address. |
| 401 | `UNAUTHORIZED` | The `Authorization` header is missing or malformed, or the API key is unknown or has been deactivated. |
| 401 | `API_KEY_EXPIRED` | The API key is past its expiry date. Create a new key in the Victoria AI app. |
| 403 | `INSUFFICIENT_SCOPE` | The API key doesn't have the scope this endpoint requires, such as `leads:write`. |
| 403 | `ORGANIZATION_DEACTIVATED` | The organization that owns this API key has been deactivated. |
| 404 | `CAMPAIGN_NOT_FOUND` | No campaign with this ID exists in your organization. |
| 404 | `NOT_FOUND` | No endpoint matches the path. A resource ID in the path that isn't a valid UUID also answers `NOT_FOUND`. |
| 409 | `DUPLICATE_WEBHOOK` | An active webhook for this URL already exists on the campaign. `details.webhook_id` identifies it. |
| 409 | `WEBHOOK_SLOT_TAKEN` | A campaign has one response webhook, and a different URL already holds this campaign's. `details.webhook_id` identifies it. Send `replace: true` to repoint that webhook at the new URL; the previous receiver then stops getting this campaign's events. |
| 413 | `PAYLOAD_TOO_LARGE` | The request body is larger than 1 MB. |
| 429 | `RATE_LIMITED` | Too many requests for this API key: more than 100 a minute to one endpoint, or 600 a minute in total. Retry after the number of seconds in the `Retry-After` header. See [Rate limits](https://docs.versionseven.ai/guides/rate-limits). |
| 500 | `INTERNAL_ERROR` | Something failed on our side. The response never includes internal details; quote its `request_id` when you contact support. |
| 503 | `UPSTREAM_TIMEOUT` | A service the API depends on timed out. The request is safe to retry. |
| 503 | `AUTH_UNAVAILABLE` | The API key couldn't be checked because the authentication service was unavailable. The request is safe to retry. |

## Response headers

| Header | Description |
| --- | --- |
| `X-Request-ID` | Correlation ID for the request, also returned as `request_id` in error bodies. Send your own `X-Request-ID`, up to 128 letters, digits, `.`, `_`, `:` or `-`, and it's used instead. |
| `RateLimit-Limit` | Requests allowed to this endpoint per minute. |
| `RateLimit-Remaining` | Requests you can still send to this endpoint right now. |
| `RateLimit-Reset` | Seconds until the endpoint's full limit is available again. |
| `Retry-After` | On a `429`: seconds to wait before retrying. |
| `Deprecation` | `true`: this endpoint is deprecated. |
| `Link` | `</v1/campaigns/{campaign_id}/webhooks>; rel="successor-version"`, naming the endpoint that replaces it. |
