curl --request OPTIONS \
--url https://app.hookie.ai/{workspace}/{project}/{webhook}const options = {method: 'OPTIONS'};
fetch('https://app.hookie.ai/{workspace}/{project}/{webhook}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.hookie.ai/{workspace}/{project}/{webhook}"
response = requests.options(url)
print(response.text){
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}CORS preflight for a page's fetch() to the public webhook URL
ING-8 (#193). Answered for an Origin in the endpoint’s cors_origins (or when they include ”*”): 204 with Access-Control-Allow-Origin (the origin, or * for any), Access-Control-Allow-Methods: POST, Access-Control-Allow-Headers: Content-Type, Idempotency-Key, and Access-Control-Max-Age: 600. Any other origin, or an endpoint with no allowed origins (the default), gets 403 and no CORS header, so the browser blocks the call. Nothing is stored or counted. Credentials are never allowed: the URL is the credential.
curl --request OPTIONS \
--url https://app.hookie.ai/{workspace}/{project}/{webhook}const options = {method: 'OPTIONS'};
fetch('https://app.hookie.ai/{workspace}/{project}/{webhook}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.hookie.ai/{workspace}/{project}/{webhook}"
response = requests.options(url)
print(response.text){
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}Headers
Optional. If a submission already exists for this tenant with the same key, the request short-circuits with 200 before the monthly quota is charged, so retries are free.
Path Parameters
Workspace (tenant) slug. Must not be one of the reserved roots reserved for app internals (api, admin, stripe, v1, assets, settings, favicon.ico, robots.txt, sitemap.xml, index.html, app.js, styles.css, export.js, portal, brand, trial-info, .well-known, mcp) — those never reach the ingest handler.
Project slug within the workspace.
Webhook slug. This high-entropy slug IS the credential — no key, token or cookie is sent. A disabled webhook answers 503 rather than 404.
Response
Preflight allowed.