The key
Grant the webhook scopes on purpose
- An organization admin creates or edits a key in XY under Organization settings → API Keys.
- Tick
webhooks:writeto create, test, change, rotate, redeliver, or delete subscriptions. - Tick
webhooks:readto list subscriptions and delivery history. - Neither scope is on by default, and neither is included in a key's default scope set.
- Personal keys and service keys both work, within that identity's role ceiling.