Skip to main content
POST
Import a configuration into a project

Authorizations

hookie_session
string
cookie
required

The console's sealed session cookie, set by WorkOS AuthKit. Mutating requests also require the X-Requested-With CSRF header.

Headers

Idempotency-Key
string

Makes a POST safe to retry for 24 hours: the same key, credential, path and body returns the stored response (Idempotent-Replayed: true) instead of running again. 422 if the key was used for a different request; 409 while the first is in flight.

Required string length: 1 - 255

Path Parameters

pid
string
required

Project id (UUID) belonging to the caller workspace.

Body

application/json

A project's configuration (DX-10, #201) — the hookie.yml shape, so hookie apply reads an export as it is. NOTHING SECRET IS IN IT: no endpoint URL (its slug is the credential), endpoint verification secret, destination signing secret or ingest key. Sources, WebSocket triggers and portals hold encrypted credentials and are listed under not_exported instead. Identity per kind: an endpoint's slug, a record view's dataset + name, everything else's name.

version
integer
project
string | null

The source project's slug; informational.

endpoints
object[]
rules
object[]
destinations
object[]
ai_agents
object[]
workflows
object[]
triggers
object[]
cron_triggers
object[]
record_views
object[]
not_exported
object[]

Informational; an import ignores it.

Response

What was created, skipped and failed.

ok
boolean
required

True when nothing failed.

created
object[]
required
skipped
object[]
required
failed
object[]
required
needs_verification_secret
object[]
required

Endpoints created verifying a provider's signature but holding NO secret (#238): the document carried the scheme and settings, never a secret. Each refuses every request with 401 until its secret is set (console Edit → Verification, or PATCH webhooks/{id} with verification {scheme, secret}). slug is the endpoint's slug as created (with any -copy suffix).