Use this API to manage the hooks that GitLab uses to notify external services about events:

You can also test a hook, inspect its event log, resend an event, and manage its custom headers and URL variables.

Managing project webhooks requires administrator access or the Maintainer or Owner role for the project. Managing group webhooks requires administrator access or the Owner role for the group. Managing system hooks requires administrator access.

List all system hooks

GET /api/v4/hooks

Lists all system hooks for the instance.

Parameters

NameTypeDescription
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20

Responses

CodeDescriptionSchema
200OKAPIEntitiesHook
400Bad Request—

Create a system hook

POST /api/v4/hooks

Creates a system hook.

Request body (application/json)

PropertyTypeDescription
branch_filter_strategyStringFilter push events by branch. Possible values are wildcard (default), regex, and all_branches
Allowed values: wildcard, regex, all_branches
custom_headersArray of objectsCustom headers
custom_headers[].key
Required
StringName of the header
Example: X-Custom-Header
custom_headers[].value
Required
StringValue of the header
Example: value
custom_webhook_templateStringCustom template for the request payload
descriptionStringDescription of the hook
enable_ssl_verificationBooleanDo SSL verification when triggering the hook
merge_requests_eventsBooleanTrigger hook on merge requests events
nameStringName of the hook
push_eventsBooleanWhen true, the hook fires on push events
push_events_branch_filterStringTrigger hook on specified branch only
repository_update_eventsBooleanTrigger hook on repository update events
signing_tokenStringHMAC signing token used to compute the webhook-signature header. Must be in whsec_<base64> format encoding a 32-byte key. Not returned in the response
tag_push_eventsBooleanWhen true, the hook fires on new tags being pushed
tokenStringSecret token to validate received payloads; this isn’t returned in the response
url
Required
StringThe URL to send the request to
Example: http://example.com/hook
url_variablesArray of objectsURL variables for interpolation
url_variables[].key
Required
StringName of the variable
Example: token
url_variables[].value
Required
StringValue of the variable
Example: 123

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesHook
400Validation error—
404Not found—
422Unprocessable entity—

Retrieve a system hook

GET /api/v4/hooks/{hook_id}

Retrieves a specified system hook.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the system hook

Responses

CodeDescriptionSchema
200OKAPIEntitiesHook
400Bad Request—
404Not found—

Create a test run

POST /api/v4/hooks/{hook_id}

Creates a test run for a webhook. Executes the webhook with mock data.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the hook

Responses

CodeDescriptionSchema
201Created—
400Bad Request—
404Not Found—

Update a system hook

PUT /api/v4/hooks/{hook_id}

Updates a specified system hook.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the system hook

Request body (application/json)

PropertyTypeDescription
branch_filter_strategyStringFilter push events by branch. Possible values are wildcard (default), regex, and all_branches
Allowed values: wildcard, regex, all_branches
custom_headersArray of objectsCustom headers
custom_headers[].key
Required
StringName of the header
Example: X-Custom-Header
custom_headers[].value
Required
StringValue of the header
Example: value
custom_webhook_templateStringCustom template for the request payload
descriptionStringDescription of the hook
enable_ssl_verificationBooleanDo SSL verification when triggering the hook
merge_requests_eventsBooleanTrigger hook on merge requests events
nameStringName of the hook
push_eventsBooleanWhen true, the hook fires on push events
push_events_branch_filterStringTrigger hook on specified branch only
repository_update_eventsBooleanTrigger hook on repository update events
signing_tokenStringHMAC signing token used to compute the webhook-signature header. Must be in whsec_<base64> format encoding a 32-byte key. Not returned in the response
tag_push_eventsBooleanWhen true, the hook fires on new tags being pushed
tokenStringSecret token to validate received payloads; this isn’t returned in the response
urlStringThe URL to send the request to
url_variablesArray of objectsURL variables for interpolation
url_variables[].key
Required
StringName of the variable
Example: token
url_variables[].value
Required
StringValue of the variable
Example: 123

Responses

CodeDescriptionSchema
200OKAPIEntitiesHook
400Validation error—
404Not found—
422Unprocessable entity—

Delete a system hook

DELETE /api/v4/hooks/{hook_id}

Deletes a specified system hook. Administrators only.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the system hook

Responses

CodeDescriptionSchema
200OKAPIEntitiesHook
400Bad Request—
404Not found—

Update a custom header

PUT /api/v4/hooks/{hook_id}/custom_headers/{key}

Updates a custom header for a specified webhook.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the hook
key
Path, required
StringThe name of the custom header

Request body (application/json)

PropertyTypeDescription
value
Required
StringThe value of the custom header

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
404Not Found—

Delete a custom header

DELETE /api/v4/hooks/{hook_id}/custom_headers/{key}

Deletes a custom header from a specified webhook.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the hook
key
Path, required
StringThe name of the custom header

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
404Not Found—

Update a URL variable

PUT /api/v4/hooks/{hook_id}/url_variables/{key}

Updates a URL variable for a specified webhook.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the hook
key
Path, required
StringThe key of the variable

Request body (application/json)

PropertyTypeDescription
value
Required
StringThe value of the variable

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
404Not Found—

Delete a URL variable

DELETE /api/v4/hooks/{hook_id}/url_variables/{key}

Deletes a URL variable from a specified webhook.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the hook
key
Path, required
StringThe key of the variable

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
404Not Found—

List all webhooks for a project

GET /api/v4/projects/{id}/hooks

Lists all webhooks for a specified project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20

Responses

CodeDescriptionSchema
200OKAPIEntitiesProjectHook
400Bad Request—
404Not Found—

Add a webhook to a project

POST /api/v4/projects/{id}/hooks

Adds a webhook to a specified project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project

Request body (application/json)

PropertyTypeDescription
branch_filter_strategyStringFilter push events by branch. Possible values are wildcard (default), regex, and all_branches
Allowed values: wildcard, regex, all_branches
confidential_issues_eventsBooleanTrigger hook on confidential issues events
confidential_note_eventsBooleanTrigger hook on confidential note (comment) events
custom_headersArray of objectsCustom headers
custom_headers[].key
Required
StringName of the header
Example: X-Custom-Header
custom_headers[].value
Required
StringValue of the header
Example: value
custom_webhook_templateStringCustom template for the request payload
deployment_eventsBooleanTrigger hook on deployment events
descriptionStringDescription of the hook
duo_flow_callback_enabledBooleanAllow Duo Agent Platform flows to send lifecycle and progress events to this webhook. A flow must reference this webhook’s ID as callback_hook_id when it starts
emoji_eventsBooleanTrigger hook on emoji events
enable_ssl_verificationBooleanDo SSL verification when triggering the hook
feature_flag_eventsBooleanTrigger hook on feature flag events
issues_eventsBooleanTrigger hook on issues events
job_eventsBooleanTrigger hook on job events
merge_requests_eventsBooleanTrigger hook on merge request events
milestone_eventsBooleanTrigger hook on milestone events
nameStringName of the hook
note_eventsBooleanTrigger hook on note (comment) events
pipeline_eventsBooleanTrigger hook on pipeline events
push_eventsBooleanTrigger hook on push events
push_events_branch_filterStringTrigger hook on specified branch only
releases_eventsBooleanTrigger hook on release events
resource_access_token_eventsBooleanTrigger hook on project access token expiry events
resource_deploy_token_eventsBooleanTrigger hook on deploy token expiry events
signing_tokenStringHMAC signing token used to compute the webhook-signature header. Must be in whsec_<base64> format encoding a 32-byte key. Not returned in the response
tag_push_eventsBooleanTrigger hook on tag push events
tokenStringSecret token to validate received payloads; this will not be returned in the response
url
Required
StringThe URL to send the request to
Example: http://example.com/hook
url_variablesArray of objectsURL variables for interpolation
url_variables[].key
Required
StringName of the variable
Example: token
url_variables[].value
Required
StringValue of the variable
Example: 123
vulnerability_eventsBooleanTrigger hook on vulnerability events
wiki_page_eventsBooleanTrigger hook on wiki events

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesProjectHook
400Validation error—
404Not found—
422Unprocessable entity—

Retrieve a project webhook

GET /api/v4/projects/{id}/hooks/{hook_id}

Retrieves a specified webhook for a project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
hook_id
Path, required
IntegerThe ID of a project hook

Responses

CodeDescriptionSchema
200OKAPIEntitiesProjectHook
400Bad Request—
404Not found—

Update a project webhook

PUT /api/v4/projects/{id}/hooks/{hook_id}

Updates a specified webhook for a project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
hook_id
Path, required
IntegerThe ID of the project hook

Request body (application/json)

PropertyTypeDescription
branch_filter_strategyStringFilter push events by branch. Possible values are wildcard (default), regex, and all_branches
Allowed values: wildcard, regex, all_branches
confidential_issues_eventsBooleanTrigger hook on confidential issues events
confidential_note_eventsBooleanTrigger hook on confidential note (comment) events
custom_headersArray of objectsCustom headers
custom_headers[].key
Required
StringName of the header
Example: X-Custom-Header
custom_headers[].value
Required
StringValue of the header
Example: value
custom_webhook_templateStringCustom template for the request payload
deployment_eventsBooleanTrigger hook on deployment events
descriptionStringDescription of the hook
duo_flow_callback_enabledBooleanAllow Duo Agent Platform flows to send lifecycle and progress events to this webhook. A flow must reference this webhook’s ID as callback_hook_id when it starts
emoji_eventsBooleanTrigger hook on emoji events
enable_ssl_verificationBooleanDo SSL verification when triggering the hook
feature_flag_eventsBooleanTrigger hook on feature flag events
issues_eventsBooleanTrigger hook on issues events
job_eventsBooleanTrigger hook on job events
merge_requests_eventsBooleanTrigger hook on merge request events
milestone_eventsBooleanTrigger hook on milestone events
nameStringName of the hook
note_eventsBooleanTrigger hook on note (comment) events
pipeline_eventsBooleanTrigger hook on pipeline events
push_eventsBooleanTrigger hook on push events
push_events_branch_filterStringTrigger hook on specified branch only
releases_eventsBooleanTrigger hook on release events
resource_access_token_eventsBooleanTrigger hook on project access token expiry events
resource_deploy_token_eventsBooleanTrigger hook on deploy token expiry events
signing_tokenStringHMAC signing token used to compute the webhook-signature header. Must be in whsec_<base64> format encoding a 32-byte key. Not returned in the response
tag_push_eventsBooleanTrigger hook on tag push events
tokenStringSecret token to validate received payloads; this will not be returned in the response
urlStringThe URL to send the request to
url_variablesArray of objectsURL variables for interpolation
url_variables[].key
Required
StringName of the variable
Example: token
url_variables[].value
Required
StringValue of the variable
Example: 123
vulnerability_eventsBooleanTrigger hook on vulnerability events
wiki_page_eventsBooleanTrigger hook on wiki events

Responses

CodeDescriptionSchema
200OKAPIEntitiesProjectHook
400Validation error—
404Not found—
422Unprocessable entity—

Delete a project webhook

DELETE /api/v4/projects/{id}/hooks/{hook_id}

Deletes a specified webhook for a project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
hook_id
Path, required
IntegerThe ID of the project hook

Responses

CodeDescriptionSchema
200OKAPIEntitiesProjectHook
400Bad Request—
404Not found—

Update a custom header

PUT /api/v4/projects/{id}/hooks/{hook_id}/custom_headers/{key}

Updates a custom header for a specified webhook.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the hook
key
Path, required
StringThe name of the custom header
id
Path, required
String or integerThe ID or URL-encoded path of the project
Example: 11

Request body (application/json)

PropertyTypeDescription
value
Required
StringThe value of the custom header

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
404Not Found—

Delete a custom header

DELETE /api/v4/projects/{id}/hooks/{hook_id}/custom_headers/{key}

Deletes a custom header from a specified webhook.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the hook
key
Path, required
StringThe name of the custom header
id
Path, required
String or integerThe ID or URL-encoded path of the project
Example: 11

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
404Not Found—

List all events

GET /api/v4/projects/{id}/hooks/{hook_id}/events

Lists all events for a specified webhook.

Parameters

NameTypeDescription
status
Query
Array of stringsHTTP status code of the event
per_page
Query
IntegerNumber of items per page
Default: 20
Maximum: 20
Minimum: 1
Example: 20
page
Query
IntegerCurrent page number
Default: 1
Example: 1
id
Path, required
String or integerThe ID or URL-encoded path of the project
Example: 11
hook_id
Path, required
IntegerThe ID of the hook

Responses

CodeDescriptionSchema
200OK—
400Bad request—
403Forbidden—
404Not found—

Resend a webhook event

POST /api/v4/projects/{id}/hooks/{hook_id}/events/{hook_log_id}/resend

Resends a webhook event. This endpoint has a rate limit of five requests per minute for each authenticated user for a given project or group. On GitLab Self-Managed and GitLab Dedicated, an administrator can change this limit in the application settings.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the hook
hook_log_id
Path, required
IntegerThe ID of the hook log entry
id
Path, required
String or integerThe ID or URL-encoded path of the project
Example: 11

Responses

CodeDescriptionSchema
201Created—
400Bad Request—
404Not found—
422Unprocessable entity—
429Too many requests—

Trigger a test webhook

POST /api/v4/projects/{id}/hooks/{hook_id}/test/{trigger}

Triggers a test webhook. This endpoint has a rate limit of five requests per minute for each authenticated user for a given project or group. On GitLab Self-Managed and GitLab Dedicated, an administrator can change this limit in the application settings.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the hook
trigger
Path, required
StringThe type of trigger hook
Allowed values: confidential_issues_events, confidential_note_events, deployment_events, emoji_events, feature_flag_events, issues_events, job_events, merge_requests_events, milestone_events, note_events, pipeline_events, push_events, releases_events, resource_access_token_events, resource_deploy_token_events, tag_push_events, wiki_page_events
Minimum length: 1
id
Path, required
String or integerThe ID or URL-encoded path of the project
Example: 11

Responses

CodeDescriptionSchema
201Created—
400Bad request—
403Forbidden—
404Not found—
422Unprocessable entity—
429Too many requests—

Update a URL variable

PUT /api/v4/projects/{id}/hooks/{hook_id}/url_variables/{key}

Updates a URL variable for a specified webhook.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the hook
key
Path, required
StringThe key of the variable
id
Path, required
String or integerThe ID or URL-encoded path of the project
Example: 11

Request body (application/json)

PropertyTypeDescription
value
Required
StringThe value of the variable

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
404Not Found—

Delete a URL variable

DELETE /api/v4/projects/{id}/hooks/{hook_id}/url_variables/{key}

Deletes a URL variable from a specified webhook.

Parameters

NameTypeDescription
hook_id
Path, required
IntegerThe ID of the hook
key
Path, required
StringThe key of the variable
id
Path, required
String or integerThe ID or URL-encoded path of the project
Example: 11

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
404Not Found—

Schemas

Objects returned by the operations above and objects nested in their request bodies.

APIEntitiesHook

PropertyTypeDescription
alert_statusStringExample: :executable
branch_filter_strategyStringExample: wildcard
created_atString (date-time)Example: 2012-05-28T04:42:42-07:00
custom_headersArray of objectsExample: [{"X-Custom-Header":"value"}]
custom_webhook_templateStringExample: {"event":"{{object_kind}}"}
descriptionStringExample: Hook description
disabled_untilString (date-time)Example: 2012-05-28T04:42:42-07:00
enable_ssl_verificationBoolean—
idInteger (int64)Example: 1
merge_requests_eventsBoolean—
nameStringExample: Hook name
organization_idIntegerExample: 1
push_eventsBoolean—
push_events_branch_filterStringExample: my-branch-*
repository_update_eventsBoolean—
signing_token_presentBooleanWhether an HMAC signing token is configured
Example: false
tag_push_eventsBoolean—
token_presentBooleanWhether a secret token is configured
Example: false
urlStringExample: https://webhook.site
url_variablesArray of objectsExample: [{"token":"secr3t"}]

APIEntitiesProjectHook

PropertyTypeDescription
alert_statusStringExample: :executable
branch_filter_strategyStringExample: wildcard
confidential_issues_eventsBoolean—
confidential_note_eventsBoolean—
created_atString (date-time)Example: 2012-05-28T04:42:42-07:00
custom_headersArray of objectsExample: [{"X-Custom-Header":"value"}]
custom_webhook_templateStringExample: {"event":"{{object_kind}}"}
deployment_eventsBoolean—
descriptionStringExample: Hook description
disabled_untilString (date-time)Example: 2012-05-28T04:42:42-07:00
duo_flow_callback_enabledBoolean—
emoji_eventsBoolean—
enable_ssl_verificationBoolean—
feature_flag_eventsBoolean—
idInteger (int64)Example: 1
issues_eventsBoolean—
job_eventsBoolean—
merge_requests_eventsBoolean—
milestone_eventsBoolean—
nameStringExample: Hook name
note_eventsBoolean—
organization_idIntegerExample: 1
pipeline_eventsBoolean—
project_idInteger (int64)Example: 1
push_eventsBoolean—
push_events_branch_filterStringExample: my-branch-*
releases_eventsBoolean—
repository_update_eventsBoolean—
resource_access_token_eventsBoolean—
resource_deploy_token_eventsBoolean—
signing_token_presentBooleanWhether an HMAC signing token is configured
Example: false
tag_push_eventsBoolean—
token_presentBooleanWhether a secret token is configured
Example: false
urlStringExample: https://webhook.site
url_variablesArray of objectsExample: [{"token":"secr3t"}]
vulnerability_eventsBoolean—
wiki_page_eventsBoolean—