> ## Documentation Index
> Fetch the complete documentation index at: https://api.vitarelay.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a webhook endpoint

> Scope `inventory:write`. The URL must be public https. The signing `secret` is in the response once; store it.
An empty `events` list subscribes to every event.




## OpenAPI

````yaml /pharmacy-api/inventory-openapi.yaml post /inventory/webhooks
openapi: 3.1.0
info:
  title: Pharmacy Inventory API
  version: 1.0.0
  description: >
    Read stock, scan-resolve barcodes, post movements, reserve stock for orders
    and subscribe to stock events.


    **Authentication.** `Authorization: Bearer vr_live_...`. A key belongs to
    your pharmacy and carries `inventory:read`

    and/or `inventory:write`. Test keys (`vr_test_...`) can read but never
    change stock.


    **Idempotency.** Every write needs an `Idempotency-Key` header (8 to 100
    visible characters). A retry with the same key

    returns the first result (HTTP 200, `idempotent: true`) and posts once.


    **Rules enforced for you.** On-hand never goes negative; orders draw only
    from released, unexpired, unreserved lots,

    first to expire first; every change is one permanent ledger entry. Rule
    failures return a machine-readable `error.code`

    and a plain-English `error.message`: `insufficient_stock` (409);
    `lot_expired`, `lot_not_released`, `lot_expiry_mismatch`,

    `expiry_required` (422); `product_not_found`, `location_not_found`,
    `lot_not_found` (404); `invalid_movement`,

    `lot_required`, `validation_error` (400).


    **Events.** Webhooks are signed: `X-Webhook-Signature: sha256=<hex
    HMAC-SHA256 of the exact request body, keyed with your

    endpoint secret>`. Headers `X-Webhook-Event`, `X-Webhook-Delivery` and
    `X-Webhook-Timestamp` accompany every request.

    Delivery is at least once with exponential backoff for about a day, then
    parked for replay. Deduplicate on

    `X-Webhook-Delivery`. Events: `stock.changed`, `stock.low`,
    `lot.status_changed`, `lot.expiring`, `sku.created`,

    `sku.updated`, `count.approved`, `temperature.excursion`.
servers:
  - url: https://vitarelay.com/api/public/v1
    description: Production
security:
  - bearer: []
paths:
  /inventory/webhooks:
    post:
      summary: Create a webhook endpoint
      description: >
        Scope `inventory:write`. The URL must be public https. The signing
        `secret` is in the response once; store it.

        An empty `events` list subscribes to every event.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WebhookRequest'
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  secret:
                    type: string
components:
  schemas:
    WebhookRequest:
      type: object
      required:
        - url
      properties:
        url:
          type: string
          format: uri
        events:
          type: array
          items:
            type: string
        description:
          type: string
  securitySchemes:
    bearer:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.