Use this API to manage the hooks that GitLab uses to notify external services about events:
- Project webhooks are limited to a single project.
- Group webhooks apply to all projects and subgroups in a group.
- System hooks apply to the entire instance.
You can also test a hook, inspect its event log, resend an event, and manage its custom headers and URL variables.
Managing project webhooks requires administrator access or the Maintainer or Owner role for the project. Managing group webhooks requires administrator access or the Owner role for the group. Managing system hooks requires administrator access.
List all system hooks
GET /api/v4/hooks
Lists all system hooks for the instance.
Parameters
| Name | Type | Description |
|---|---|---|
pageQuery | Integer | Current page number Default: 1Example: 1 |
per_Query | Integer | Number of items per page Default: 20Example: 20 |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Bad Request | — |
Create a system hook
POST /api/v4/hooks
Creates a system hook.
Request body (application/json)
| Property | Type | Description |
|---|---|---|
branch_ | String | Filter push events by branch.wildcard (default),regex,all_Allowed values: wildcard,regex,all_ |
custom_ | Array of objects | Custom headers |
custom_Required | String | Name of the header Example: X- |
custom_Required | String | Value of the header Example: value |
custom_ | String | Custom template for the request payload |
description | String | Description of the hook |
enable_ | Boolean | Do SSL verification when triggering the hook |
merge_ | Boolean | Trigger hook on merge requests events |
name | String | Name of the hook |
push_ | Boolean | When true, |
push_ | String | Trigger hook on specified branch only |
repository_ | Boolean | Trigger hook on repository update events |
signing_ | String | HMAC signing token used to compute the webhook- |
tag_ | Boolean | When true, |
token | String | Secret token to validate received payloads; this isn’t returned in the response |
urlRequired | String | The URL to send the request to Example: http: |
url_ | Array of objects | URL variables for interpolation |
url_Required | String | Name of the variable Example: token |
url_Required | String | Value of the variable Example: 123 |
Responses
| Code | Description | Schema |
|---|---|---|
201 | Created | APIEntities |
400 | Validation error | — |
404 | Not found | — |
422 | Unprocessable entity | — |
Retrieve a system hook
GET /api/v4/hooks/{hook_id}
Retrieves a specified system hook.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the system hook |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Bad Request | — |
404 | Not found | — |
Create a test run
POST /api/v4/hooks/{hook_id}
Creates a test run for a webhook. Executes the webhook with mock data.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the hook |
Responses
| Code | Description | Schema |
|---|---|---|
201 | Created | — |
400 | Bad Request | — |
404 | Not Found | — |
Update a system hook
PUT /api/v4/hooks/{hook_id}
Updates a specified system hook.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the system hook |
Request body (application/json)
| Property | Type | Description |
|---|---|---|
branch_ | String | Filter push events by branch.wildcard (default),regex,all_Allowed values: wildcard,regex,all_ |
custom_ | Array of objects | Custom headers |
custom_Required | String | Name of the header Example: X- |
custom_Required | String | Value of the header Example: value |
custom_ | String | Custom template for the request payload |
description | String | Description of the hook |
enable_ | Boolean | Do SSL verification when triggering the hook |
merge_ | Boolean | Trigger hook on merge requests events |
name | String | Name of the hook |
push_ | Boolean | When true, |
push_ | String | Trigger hook on specified branch only |
repository_ | Boolean | Trigger hook on repository update events |
signing_ | String | HMAC signing token used to compute the webhook- |
tag_ | Boolean | When true, |
token | String | Secret token to validate received payloads; this isn’t returned in the response |
url | String | The URL to send the request to |
url_ | Array of objects | URL variables for interpolation |
url_Required | String | Name of the variable Example: token |
url_Required | String | Value of the variable Example: 123 |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Validation error | — |
404 | Not found | — |
422 | Unprocessable entity | — |
Delete a system hook
DELETE /api/v4/hooks/{hook_id}
Deletes a specified system hook. Administrators only.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the system hook |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Bad Request | — |
404 | Not found | — |
Update a custom header
PUT /api/v4/hooks/{hook_id}/custom_headers/{key}
Updates a custom header for a specified webhook.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the hook |
keyPath, | String | The name of the custom header |
Request body (application/json)
| Property | Type | Description |
|---|---|---|
valueRequired | String | The value of the custom header |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | — |
400 | Bad Request | — |
404 | Not Found | — |
Delete a custom header
DELETE /api/v4/hooks/{hook_id}/custom_headers/{key}
Deletes a custom header from a specified webhook.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the hook |
keyPath, | String | The name of the custom header |
Responses
| Code | Description | Schema |
|---|---|---|
204 | No Content | — |
400 | Bad Request | — |
404 | Not Found | — |
Update a URL variable
PUT /api/v4/hooks/{hook_id}/url_variables/{key}
Updates a URL variable for a specified webhook.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the hook |
keyPath, | String | The key of the variable |
Request body (application/json)
| Property | Type | Description |
|---|---|---|
valueRequired | String | The value of the variable |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | — |
400 | Bad Request | — |
404 | Not Found | — |
Delete a URL variable
DELETE /api/v4/hooks/{hook_id}/url_variables/{key}
Deletes a URL variable from a specified webhook.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the hook |
keyPath, | String | The key of the variable |
Responses
| Code | Description | Schema |
|---|---|---|
204 | No Content | — |
400 | Bad Request | — |
404 | Not Found | — |
List all webhooks for a project
GET /api/v4/projects/{id}/hooks
Lists all webhooks for a specified project.
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
pageQuery | Integer | Current page number Default: 1Example: 1 |
per_Query | Integer | Number of items per page Default: 20Example: 20 |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Bad Request | — |
404 | Not Found | — |
Add a webhook to a project
POST /api/v4/projects/{id}/hooks
Adds a webhook to a specified project.
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
Request body (application/json)
| Property | Type | Description |
|---|---|---|
branch_ | String | Filter push events by branch.wildcard (default),regex,all_Allowed values: wildcard,regex,all_ |
confidential_ | Boolean | Trigger hook on confidential issues events |
confidential_ | Boolean | Trigger hook on confidential note (comment) events |
custom_ | Array of objects | Custom headers |
custom_Required | String | Name of the header Example: X- |
custom_Required | String | Value of the header Example: value |
custom_ | String | Custom template for the request payload |
deployment_ | Boolean | Trigger hook on deployment events |
description | String | Description of the hook |
duo_ | Boolean | Allow Duo Agent Platform flows to send lifecycle and progress events to this webhook. |
emoji_ | Boolean | Trigger hook on emoji events |
enable_ | Boolean | Do SSL verification when triggering the hook |
feature_ | Boolean | Trigger hook on feature flag events |
issues_ | Boolean | Trigger hook on issues events |
job_ | Boolean | Trigger hook on job events |
merge_ | Boolean | Trigger hook on merge request events |
milestone_ | Boolean | Trigger hook on milestone events |
name | String | Name of the hook |
note_ | Boolean | Trigger hook on note (comment) events |
pipeline_ | Boolean | Trigger hook on pipeline events |
push_ | Boolean | Trigger hook on push events |
push_ | String | Trigger hook on specified branch only |
releases_ | Boolean | Trigger hook on release events |
resource_ | Boolean | Trigger hook on project access token expiry events |
resource_ | Boolean | Trigger hook on deploy token expiry events |
signing_ | String | HMAC signing token used to compute the webhook- |
tag_ | Boolean | Trigger hook on tag push events |
token | String | Secret token to validate received payloads; this will not be returned in the response |
urlRequired | String | The URL to send the request to Example: http: |
url_ | Array of objects | URL variables for interpolation |
url_Required | String | Name of the variable Example: token |
url_Required | String | Value of the variable Example: 123 |
vulnerability_ | Boolean | Trigger hook on vulnerability events |
wiki_ | Boolean | Trigger hook on wiki events |
Responses
| Code | Description | Schema |
|---|---|---|
201 | Created | APIEntities |
400 | Validation error | — |
404 | Not found | — |
422 | Unprocessable entity | — |
Retrieve a project webhook
GET /api/v4/projects/{id}/hooks/{hook_id}
Retrieves a specified webhook for a project.
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
hook_Path, | Integer | The ID of a project hook |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Bad Request | — |
404 | Not found | — |
Update a project webhook
PUT /api/v4/projects/{id}/hooks/{hook_id}
Updates a specified webhook for a project.
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
hook_Path, | Integer | The ID of the project hook |
Request body (application/json)
| Property | Type | Description |
|---|---|---|
branch_ | String | Filter push events by branch.wildcard (default),regex,all_Allowed values: wildcard,regex,all_ |
confidential_ | Boolean | Trigger hook on confidential issues events |
confidential_ | Boolean | Trigger hook on confidential note (comment) events |
custom_ | Array of objects | Custom headers |
custom_Required | String | Name of the header Example: X- |
custom_Required | String | Value of the header Example: value |
custom_ | String | Custom template for the request payload |
deployment_ | Boolean | Trigger hook on deployment events |
description | String | Description of the hook |
duo_ | Boolean | Allow Duo Agent Platform flows to send lifecycle and progress events to this webhook. |
emoji_ | Boolean | Trigger hook on emoji events |
enable_ | Boolean | Do SSL verification when triggering the hook |
feature_ | Boolean | Trigger hook on feature flag events |
issues_ | Boolean | Trigger hook on issues events |
job_ | Boolean | Trigger hook on job events |
merge_ | Boolean | Trigger hook on merge request events |
milestone_ | Boolean | Trigger hook on milestone events |
name | String | Name of the hook |
note_ | Boolean | Trigger hook on note (comment) events |
pipeline_ | Boolean | Trigger hook on pipeline events |
push_ | Boolean | Trigger hook on push events |
push_ | String | Trigger hook on specified branch only |
releases_ | Boolean | Trigger hook on release events |
resource_ | Boolean | Trigger hook on project access token expiry events |
resource_ | Boolean | Trigger hook on deploy token expiry events |
signing_ | String | HMAC signing token used to compute the webhook- |
tag_ | Boolean | Trigger hook on tag push events |
token | String | Secret token to validate received payloads; this will not be returned in the response |
url | String | The URL to send the request to |
url_ | Array of objects | URL variables for interpolation |
url_Required | String | Name of the variable Example: token |
url_Required | String | Value of the variable Example: 123 |
vulnerability_ | Boolean | Trigger hook on vulnerability events |
wiki_ | Boolean | Trigger hook on wiki events |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Validation error | — |
404 | Not found | — |
422 | Unprocessable entity | — |
Delete a project webhook
DELETE /api/v4/projects/{id}/hooks/{hook_id}
Deletes a specified webhook for a project.
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
hook_Path, | Integer | The ID of the project hook |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Bad Request | — |
404 | Not found | — |
Update a custom header
PUT /api/v4/projects/{id}/hooks/{hook_id}/custom_headers/{key}
Updates a custom header for a specified webhook.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the hook |
keyPath, | String | The name of the custom header |
idPath, | String or integer | The ID or URL- Example: 11 |
Request body (application/json)
| Property | Type | Description |
|---|---|---|
valueRequired | String | The value of the custom header |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | — |
400 | Bad Request | — |
404 | Not Found | — |
Delete a custom header
DELETE /api/v4/projects/{id}/hooks/{hook_id}/custom_headers/{key}
Deletes a custom header from a specified webhook.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the hook |
keyPath, | String | The name of the custom header |
idPath, | String or integer | The ID or URL- Example: 11 |
Responses
| Code | Description | Schema |
|---|---|---|
204 | No Content | — |
400 | Bad Request | — |
404 | Not Found | — |
List all events
GET /api/v4/projects/{id}/hooks/{hook_id}/events
Lists all events for a specified webhook.
Parameters
| Name | Type | Description |
|---|---|---|
statusQuery | Array of strings | HTTP status code of the event |
per_Query | Integer | Number of items per page Default: 20Maximum: 20Minimum: 1Example: 20 |
pageQuery | Integer | Current page number Default: 1Example: 1 |
idPath, | String or integer | The ID or URL- Example: 11 |
hook_Path, | Integer | The ID of the hook |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | — |
400 | Bad request | — |
403 | Forbidden | — |
404 | Not found | — |
Resend a webhook event
POST /api/v4/projects/{id}/hooks/{hook_id}/events/{hook_log_id}/resend
Resends a webhook event. This endpoint has a rate limit of five requests per minute for each authenticated user for a given project or group. On GitLab Self-Managed and GitLab Dedicated, an administrator can change this limit in the application settings.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the hook |
hook_Path, | Integer | The ID of the hook log entry |
idPath, | String or integer | The ID or URL- Example: 11 |
Responses
| Code | Description | Schema |
|---|---|---|
201 | Created | — |
400 | Bad Request | — |
404 | Not found | — |
422 | Unprocessable entity | — |
429 | Too many requests | — |
Trigger a test webhook
POST /api/v4/projects/{id}/hooks/{hook_id}/test/{trigger}
Triggers a test webhook. This endpoint has a rate limit of five requests per minute for each authenticated user for a given project or group. On GitLab Self-Managed and GitLab Dedicated, an administrator can change this limit in the application settings.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the hook |
triggerPath, | String | The type of trigger hook Allowed values: confidential_,confidential_,deployment_,emoji_,feature_,issues_,job_,merge_,milestone_,note_,pipeline_,push_,releases_,resource_,resource_,tag_,wiki_Minimum length: 1 |
idPath, | String or integer | The ID or URL- Example: 11 |
Responses
| Code | Description | Schema |
|---|---|---|
201 | Created | — |
400 | Bad request | — |
403 | Forbidden | — |
404 | Not found | — |
422 | Unprocessable entity | — |
429 | Too many requests | — |
Update a URL variable
PUT /api/v4/projects/{id}/hooks/{hook_id}/url_variables/{key}
Updates a URL variable for a specified webhook.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the hook |
keyPath, | String | The key of the variable |
idPath, | String or integer | The ID or URL- Example: 11 |
Request body (application/json)
| Property | Type | Description |
|---|---|---|
valueRequired | String | The value of the variable |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | — |
400 | Bad Request | — |
404 | Not Found | — |
Delete a URL variable
DELETE /api/v4/projects/{id}/hooks/{hook_id}/url_variables/{key}
Deletes a URL variable from a specified webhook.
Parameters
| Name | Type | Description |
|---|---|---|
hook_Path, | Integer | The ID of the hook |
keyPath, | String | The key of the variable |
idPath, | String or integer | The ID or URL- Example: 11 |
Responses
| Code | Description | Schema |
|---|---|---|
204 | No Content | — |
400 | Bad Request | — |
404 | Not Found | — |
Schemas
Objects returned by the operations above and objects nested in their request bodies.
APIEntitiesHook
| Property | Type | Description |
|---|---|---|
alert_ | String | Example:: |
branch_ | String | Example:wildcard |
created_ | String (date- | Example:2012- |
custom_ | Array of objects | Example:[{"X- |
custom_ | String | Example:{"event": |
description | String | Example:Hook description |
disabled_ | String (date- | Example:2012- |
enable_ | Boolean | — |
id | Integer (int64) | Example:1 |
merge_ | Boolean | — |
name | String | Example:Hook name |
organization_ | Integer | Example:1 |
push_ | Boolean | — |
push_ | String | Example:my- |
repository_ | Boolean | — |
signing_ | Boolean | Whether an HMAC signing token is configured Example: false |
tag_ | Boolean | — |
token_ | Boolean | Whether a secret token is configured Example: false |
url | String | Example:https: |
url_ | Array of objects | Example:[{"token": |
APIEntitiesProjectHook
| Property | Type | Description |
|---|---|---|
alert_ | String | Example:: |
branch_ | String | Example:wildcard |
confidential_ | Boolean | — |
confidential_ | Boolean | — |
created_ | String (date- | Example:2012- |
custom_ | Array of objects | Example:[{"X- |
custom_ | String | Example:{"event": |
deployment_ | Boolean | — |
description | String | Example:Hook description |
disabled_ | String (date- | Example:2012- |
duo_ | Boolean | — |
emoji_ | Boolean | — |
enable_ | Boolean | — |
feature_ | Boolean | — |
id | Integer (int64) | Example:1 |
issues_ | Boolean | — |
job_ | Boolean | — |
merge_ | Boolean | — |
milestone_ | Boolean | — |
name | String | Example:Hook name |
note_ | Boolean | — |
organization_ | Integer | Example:1 |
pipeline_ | Boolean | — |
project_ | Integer (int64) | Example:1 |
push_ | Boolean | — |
push_ | String | Example:my- |
releases_ | Boolean | — |
repository_ | Boolean | — |
resource_ | Boolean | — |
resource_ | Boolean | — |
signing_ | Boolean | Whether an HMAC signing token is configured Example: false |
tag_ | Boolean | — |
token_ | Boolean | Whether a secret token is configured Example: false |
url | String | Example:https: |
url_ | Array of objects | Example:[{"token": |
vulnerability_ | Boolean | — |
wiki_ | Boolean | — |