> ## Documentation Index
> Fetch the complete documentation index at: https://partner-docs.contro.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Update webhook config

> Update the partner's webhook configuration



## OpenAPI

````yaml /partner-openapi.json patch /partner/webhooks/config
openapi: 3.1.0
info:
  title: Contro Partner API
  version: 1.0.0
  license:
    name: Proprietary
    url: https://contro.me/terms
  description: >-
    The Contro Partner API enables Card-as-a-Service (CaaS) partners to
    programmatically issue cards, manage cardholders, and monitor transactions.


    ## Authentication


    All requests require your partner API key in the `x-contro-api-key` header:


    ```

    x-contro-api-key: sk_live_...

    ```


    Use `sk_test_*` keys for sandbox and `sk_live_*` keys for production.


    ## Rate Limits


    The API allows 1,000 requests per minute per API key. When exceeded,
    responses return HTTP 429 with a `Retry-After` header.


    ## Pagination


    List endpoints use page-based pagination:


    ```json

    {
      "data": [...],
      "page": 1,
      "limit": 20,
      "total": 137
    }

    ```


    Pass `?page=2&limit=20` to paginate. `limit` accepts 1–100 (default 20);
    `page` defaults to 1.


    ## Errors


    All errors return:


    ```json

    {
      "success": false,
      "error": "Human-readable message"
    }

    ```
servers:
  - url: https://api.contro.me/v1
    description: Production server for live traffic
  - url: https://stg-api.contro.dev/v1
    description: Sandbox environment for testing
security:
  - apiKey: []
paths:
  /partner/webhooks/config:
    patch:
      tags:
        - Partner - Webhooks
      summary: Update webhook config
      description: Update the partner's webhook configuration
      operationId: updateWebhookConfig
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                webhookUrl:
                  type: string
                  format: uri
                  description: HTTPS URL to receive events. Must use https://
                  example: https://your-app.com/webhooks/contro
                webhookSecret:
                  type: string
                  minLength: 16
                  description: >-
                    Secret for HMAC-SHA256 signature verification. Min 16
                    characters
                  example: whsec_your_secret_min_16_chars
                subscribedEvents:
                  type: array
                  items:
                    type: string
                  description: Event types to subscribe to
                  example:
                    - card.transaction
                    - cardholder.kyc.updated
                    - balance.low
      responses:
        '200':
          description: Webhook config updated
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - true
                required:
                  - success
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '404':
          description: Not Found
        '429':
          description: Rate Limited
        '500':
          description: Internal Server Error
components:
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: x-contro-api-key
      description: Partner API key (sk_live_* for production, sk_test_* for sandbox)

````