Action API
POST/webhooksAPI v2

Webhooks

2 min readWebhooks

POST /webhooks

Register a signed outbound webhook for one or more Taskade events

Base URL: https://www.taskade.com/api/v2

Authentication

Send a personal access token or an OAuth 2.0 access token as a bearer token. Create a personal access token at taskade.com/settings/api.

Http
Authorization: Bearer tskdp_your_token_here

Request body

application/json

Field Type Required Description
targetUrl string Yes
events string[] Yes
spaceIds string[] No

Example request

Bash
curl -X POST "https://www.taskade.com/api/v2/webhooks" \
  -H "Authorization: Bearer $TASKADE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"targetUrl":"<targetUrl>","events":["task.due"]}'

Responses

200 — Default response
Field Type Required Description
ok boolean Yes
webhook object Yes
secret string Yes HMAC signing secret - shown once. Store it now.

Errors

Errors return an ok: false envelope. Rate limiting returns 429 with x-rate-limit-limit, x-rate-limit-remaining and x-rate-limit-reset headers — x-rate-limit-reset is the number of seconds until the window reopens. Retry-After is not sent, so schedule retries from x-rate-limit-reset; retrying sooner will fail again.

Json
{ "ok": false, "message": "Unauthorized", "code": "UNAUTHORIZED" }

Rate limits for this version: enforced per endpoint; ceilings are not published and can change without notice. A 429 response carries x-rate-limit-limit, x-rate-limit-remaining, and x-rate-limit-reset (seconds until the window reopens) — back off from those headers rather than hardcoding numbers. If you need sustained throughput, prefer batching (operations like /createTask accept arrays) over tightening polling loops. See Rate limits.