X-API-Key: sk_*. Supabase Bearer is NOT accepted on webhook endpoints.X-Managed-Profile-Id returns 400, and a direct managed-child credential returns 403. An unselected manager key remains manager-owned and cannot subscribe to a child-owned quote.quoteId must belong to a quote created with your key (any other quote returns 404). The callback URL must use HTTPS, must not embed credentials, and must resolve to a publicly routable address; private or reserved IP ranges are rejected.curl --location '/v1/webhook' \
--header 'X-API-Key: <api-key>' \
--header 'Content-Type: application/json' \
--data '{
"events": [
"string"
],
"quoteId": "string",
"sessionId": "string",
"url": "string"
}'{
"createdAt": "2025-10-01T16:21:04.648Z",
"events": [
"TRANSACTION_CREATED",
"STATUS_CHANGE"
],
"id": "340ba946-f3f3-4007-893c-3374bfcd096b",
"isActive": true,
"quoteId": "3258910e-93ee-443e-b793-28cc1d4ccdf3",
"sessionId": null,
"url": "https://your-website.com"
}