Ping a webhook subscription
Runs a synchronous, signed webhook probe through the production delivery path and returns the classified result. A successful ping flips a webhook subscription from pending_verification to active. A classified probe failure is still a 200 (the probe ran and produced a verdict). This route is naturally idempotent and requires no X-Idempotency header. A queue subscription has no ping probe and returns 422 probe_unsupported_for_sink_kind.
Authorizations
A bearer JWT issued by plugin-auth (lib-auth). The tenant identity is resolved from the validated token claims; the /v1 surface never reads a tenant from the body, path, or query. Machine callers obtain a token via the plugin-auth client-credentials flow. The /admin surface authorizes against an operator scope and carries no tenant context.
Path Parameters
The unique identifier of the subscription (UUIDv7).
Response
The probe ran; the body carries the classified attempt result.
The classified result of a synchronous probe (ping, verify, or credential write). A classified failure is still returned with HTTP 200 — the probe ran and produced a verdict. It carries no secret, endpoint, or detail string.
The classified verdict of a synchronous probe.
ok, failed The target's protocol status. For webhook probes, the HTTP status (0 when none applies, e.g. a transport error or a blocked endpoint). For queue-kind credential probes, always 0.
200
A frozen taxonomy token classifying a failure. Empty on success.
""

