curl --request POST \
--url https://app.hookie.ai/admin/api/projects/{pid}/config \
--header 'Content-Type: application/json' \
--cookie hookie_session= \
--data '
{
"version": 1,
"project": "<string>",
"endpoints": [
{}
],
"rules": [
{}
],
"destinations": [
{}
],
"ai_agents": [
{}
],
"workflows": [
{}
],
"triggers": [
{}
],
"cron_triggers": [
{}
],
"record_views": [
{}
],
"not_exported": [
{
"kind": "<string>",
"count": 123,
"reason": "<string>"
}
]
}
'const options = {
method: 'POST',
headers: {cookie: 'hookie_session=', 'Content-Type': 'application/json'},
body: JSON.stringify({
version: 1,
project: '<string>',
endpoints: [{}],
rules: [{}],
destinations: [{}],
ai_agents: [{}],
workflows: [{}],
triggers: [{}],
cron_triggers: [{}],
record_views: [{}],
not_exported: [{kind: '<string>', count: 123, reason: '<string>'}]
})
};
fetch('https://app.hookie.ai/admin/api/projects/{pid}/config', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.hookie.ai/admin/api/projects/{pid}/config"
payload = {
"version": 1,
"project": "<string>",
"endpoints": [{}],
"rules": [{}],
"destinations": [{}],
"ai_agents": [{}],
"workflows": [{}],
"triggers": [{}],
"cron_triggers": [{}],
"record_views": [{}],
"not_exported": [
{
"kind": "<string>",
"count": 123,
"reason": "<string>"
}
]
}
headers = {
"cookie": "hookie_session=",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"ok": true,
"created": [
{
"kind": "<string>",
"name": "<string>",
"id": "<string>",
"note": "<string>"
}
],
"skipped": [
{
"kind": "<string>",
"name": "<string>",
"reason": "<string>"
}
],
"failed": [
{
"kind": "<string>",
"name": "<string>",
"error": "<string>"
}
],
"needs_verification_secret": [
{
"id": "<string>",
"name": "<string>",
"slug": "<string>",
"scheme": "<string>"
}
]
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}Import a configuration into a project
Create what the document describes, in dependency order (AI agents, record views, rules, endpoints, destinations, workflows, AI triggers, cron triggers), each through its own create route — so it is validated, plan-limited and audited as a create by hand is, and every endpoint gets a NEW URL and every destination a NEW signing secret (reveal it with GET destinations//secret). An endpoint that verifies a provider’s signature is created with its scheme and settings but NO secret, so it refuses every request with 401 until one is set, and is listed under needs_verification_secret (#238). A resource whose identity already exists in the project is skipped, never overwritten. A failed create is reported and the import carries on. JSON only; import YAML with hookie apply. Write role required; cron triggers need owner or admin.
curl --request POST \
--url https://app.hookie.ai/admin/api/projects/{pid}/config \
--header 'Content-Type: application/json' \
--cookie hookie_session= \
--data '
{
"version": 1,
"project": "<string>",
"endpoints": [
{}
],
"rules": [
{}
],
"destinations": [
{}
],
"ai_agents": [
{}
],
"workflows": [
{}
],
"triggers": [
{}
],
"cron_triggers": [
{}
],
"record_views": [
{}
],
"not_exported": [
{
"kind": "<string>",
"count": 123,
"reason": "<string>"
}
]
}
'const options = {
method: 'POST',
headers: {cookie: 'hookie_session=', 'Content-Type': 'application/json'},
body: JSON.stringify({
version: 1,
project: '<string>',
endpoints: [{}],
rules: [{}],
destinations: [{}],
ai_agents: [{}],
workflows: [{}],
triggers: [{}],
cron_triggers: [{}],
record_views: [{}],
not_exported: [{kind: '<string>', count: 123, reason: '<string>'}]
})
};
fetch('https://app.hookie.ai/admin/api/projects/{pid}/config', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.hookie.ai/admin/api/projects/{pid}/config"
payload = {
"version": 1,
"project": "<string>",
"endpoints": [{}],
"rules": [{}],
"destinations": [{}],
"ai_agents": [{}],
"workflows": [{}],
"triggers": [{}],
"cron_triggers": [{}],
"record_views": [{}],
"not_exported": [
{
"kind": "<string>",
"count": 123,
"reason": "<string>"
}
]
}
headers = {
"cookie": "hookie_session=",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"ok": true,
"created": [
{
"kind": "<string>",
"name": "<string>",
"id": "<string>",
"note": "<string>"
}
],
"skipped": [
{
"kind": "<string>",
"name": "<string>",
"reason": "<string>"
}
],
"failed": [
{
"kind": "<string>",
"name": "<string>",
"error": "<string>"
}
],
"needs_verification_secret": [
{
"id": "<string>",
"name": "<string>",
"slug": "<string>",
"scheme": "<string>"
}
]
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}Authorizations
The console's sealed session cookie, set by WorkOS AuthKit. Mutating requests also require the X-Requested-With CSRF header.
Headers
Makes a POST safe to retry for 24 hours: the same key, credential, path and body returns the stored response (Idempotent-Replayed: true) instead of running again. 422 if the key was used for a different request; 409 while the first is in flight.
1 - 255Path Parameters
Project id (UUID) belonging to the caller workspace.
Body
A project's configuration (DX-10, #201) — the hookie.yml shape, so hookie apply reads an export as it is. NOTHING SECRET IS IN IT: no endpoint URL (its slug is the credential), endpoint verification secret, destination signing secret or ingest key. Sources, WebSocket triggers and portals hold encrypted credentials and are listed under not_exported instead. Identity per kind: an endpoint's slug, a record view's dataset + name, everything else's name.
The source project's slug; informational.
Informational; an import ignores it.
Show child attributes
Show child attributes
Response
What was created, skipped and failed.
True when nothing failed.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Endpoints created verifying a provider's signature but holding NO secret (#238): the document carried the scheme and settings, never a secret. Each refuses every request with 401 until its secret is set (console Edit → Verification, or PATCH webhooks/{id} with verification {scheme, secret}). slug is the endpoint's slug as created (with any -copy suffix).
Show child attributes
Show child attributes