> ## Documentation Index
> Fetch the complete documentation index at: https://www.tryleap.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Leap's API is at https://api.tryleap.ai. Send the key in the x-api-key header or as Authorization: Bearer; keys start with leap_.
> Take model IDs and input schemas from GET /v1/models/{creator}/{name}, or from https://api.tryleap.ai/v1/public/models without a key. Never guess an input field: unknown fields are a 400.
> Model inputs take uploaded file IDs (file_...), never URLs.
> To give a coding agent the whole API, install the Leap skill: curl -fsSL https://www.tryleap.ai/install.sh | sh
> The full OpenAPI 3.1 spec is at https://www.tryleap.ai/docs/openapi.json.

# Create a webhook endpoint

> Starts sending your workspace's events to an https URL: every type by default (`["*"]`, including types added later), or the ones you list. Runs started from the API, the studio and MCP all send events. The answer holds the endpoint's signing secret, shown only here and when you rotate it. A workspace can have up to 16 endpoints; one more answers `409`.

Needs an API key with the `generations:write` scope.



## OpenAPI

````yaml /openapi.json post /v1/webhook_endpoints
openapi: 3.1.0
info:
  title: Leap API
  version: 1.0.0
  description: >-
    One API for the best image, video and audio models. Every request goes to
    `https://api.tryleap.ai` with your API key in the `x-api-key` header, or as
    `Authorization: Bearer leap_...`. Create a key at
    https://app.tryleap.ai/go/api.


    Guides, examples and the errors list are at https://www.tryleap.ai/docs.
servers:
  - url: https://api.tryleap.ai
security:
  - ApiKey: []
  - Bearer: []
tags:
  - name: Models
    description: >-
      Every model and preset you can run, with its price and the JSON Schema of
      the input it takes.
  - name: Quotes
    description: >-
      The exact price of a run before you start it, with its input checked and
      its defaults filled in.
  - name: Generations
    description: >-
      A generation is one run of a model or preset: queued, then running, then
      succeeded, failed or canceled. Only a succeeded run is charged.
  - name: Batches
    description: >-
      Up to 50 generations priced and held together in one request, each then
      run as its own generation.
  - name: Webhooks
    description: >-
      URLs your workspace's events are POSTed to, signed following Standard
      Webhooks, and the default secret for the `webhook` URL a request names.
  - name: Events
    description: >-
      What happened in your workspace, kept 30 days, with each delivery to your
      webhooks and a way to send one again.
  - name: Files
    description: >-
      Photos, videos and sounds that models take as input. Upload one, then pass
      its `file_...` ID in the input field the model's schema names.
  - name: Credits
    description: Your workspace's balance in US dollars.
externalDocs:
  url: https://www.tryleap.ai/docs
paths:
  /v1/webhook_endpoints:
    post:
      tags:
        - Webhooks
      summary: Create a webhook endpoint
      description: >-
        Starts sending your workspace's events to an https URL: every type by
        default (`["*"]`, including types added later), or the ones you list.
        Runs started from the API, the studio and MCP all send events. The
        answer holds the endpoint's signing secret, shown only here and when you
        rotate it. A workspace can have up to 16 endpoints; one more answers
        `409`.


        Needs an API key with the `generations:write` scope.
      operationId: createWebhookEndpoint
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WebhookEndpointRequest'
      responses:
        '201':
          description: The endpoint, with its signing secret.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Limit:
              $ref: '#/components/headers/RateLimit-Limit'
            RateLimit-Remaining:
              $ref: '#/components/headers/RateLimit-Remaining'
            RateLimit-Reset:
              $ref: '#/components/headers/RateLimit-Reset'
            Location:
              schema:
                type: string
                description: The new resource's path, such as `/v1/generations/gen_...`.
          content:
            application/json:
              example:
                id: we_5Tq8Lm2Xv9Kr4Wn7Bc1Yd3Hp
                object: webhook_endpoint
                url: https://example.com/webhooks/leap
                description: Production renders
                events:
                  - generation.succeeded
                  - generation.failed
                disabled: false
                disabled_reason: null
                created_at: '2026-10-04T18:20:03.441Z'
                updated_at: '2026-10-04T18:20:03.441Z'
                secret: whsec_foO4NH7H4fkZ/TBkV6oqbUTlZgWKMsflfyzrjNDfrQs=
              schema:
                $ref: '#/components/schemas/WebhookEndpointWithSecret'
        '400':
          $ref: '#/components/responses/InvalidParameterOrConflictingCredentials'
        '401':
          $ref: '#/components/responses/AuthenticationRequired'
        '403':
          $ref: '#/components/responses/PermissionDenied'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimitExceeded'
components:
  schemas:
    WebhookEndpointRequest:
      type: object
      properties:
        url:
          type: string
          maxLength: 2048
          format: uri
          description: >-
            Where Leap POSTs events: an https URL that answers 2xx within 15
            seconds.
        events:
          description: >-
            The event types to send. ["*"], the default, sends every type,
            including types added later.
          minItems: 1
          maxItems: 4
          type: array
          items:
            type: string
            enum:
              - '*'
              - generation.succeeded
              - generation.failed
              - generation.canceled
              - batch.completed
        description:
          default: null
          description: A note for people, such as which app this is.
          anyOf:
            - type: string
              maxLength: 500
            - type: 'null'
      required:
        - url
      additionalProperties: false
    WebhookEndpointWithSecret:
      type: object
      properties:
        id:
          type: string
          description: The endpoint's ID, `we_...`.
        object:
          type: string
          const: webhook_endpoint
        url:
          type: string
          description: Where Leap POSTs events.
        description:
          description: Your note, if any.
          type:
            - string
            - 'null'
        events:
          type: array
          items:
            type: string
          description: >-
            The event types it gets; ["*"] for every type, including types added
            later.
        disabled:
          type: boolean
          description: Whether deliveries to it are stopped.
        disabled_reason:
          description: >-
            Why Leap disabled the endpoint, such as every delivery failing for
            72 hours; null when it is on or you turned it off.
          type:
            - string
            - 'null'
        created_at:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z))$
          description: When it was created.
        updated_at:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z))$
          description: When it last changed.
        secret:
          type: string
          description: >-
            The signing secret, whsec_ and base64. Shown only here: keep it in
            your server's environment.
      required:
        - id
        - object
        - url
        - description
        - events
        - disabled
        - disabled_reason
        - created_at
        - updated_at
        - secret
      additionalProperties: false
      description: >-
        An endpoint with its signing secret, as create and rotate_secret return
        it.
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - invalid_request_error
                - rate_limit_error
                - authentication_error
                - permission_error
                - conflict_error
                - billing_error
                - api_error
              description: >-
                The kind of error. Branch on `type` and `code`, never on
                `message`.
            code:
              type: string
              enum:
                - invalid_parameter
                - invalid_request
                - conflicting_credentials
                - placeholder_in_path
                - method_not_allowed
                - payload_too_large
                - unsupported_media_type
                - ip_rate_limit_exceeded
                - authentication_required
                - missing_api_key
                - invalid_api_key
                - permission_denied
                - not_found
                - resource_not_found
                - gone
                - conflict
                - rate_limit_exceeded
                - insufficient_credit
                - service_unavailable
                - internal_error
              description: >-
                A stable code for this error. Each one is explained at
                https://www.tryleap.ai/docs/errors.
            message:
              type: string
              description: >-
                What went wrong, written for a person. It can change; don't
                parse it.
            param:
              description: >-
                For a `400`, the field at fault, such as `input.prompt`;
                otherwise null.
              type:
                - string
                - 'null'
            doc_url:
              description: A page that explains this error, when there is one.
              type:
                - string
                - 'null'
            request_id:
              type: string
              description: >-
                This request's ID, as in the `X-Request-Id` header. Include it
                when you contact support.
          required:
            - type
            - code
            - message
            - param
            - doc_url
            - request_id
          additionalProperties: false
      required:
        - error
      additionalProperties: false
  headers:
    X-Request-Id:
      required: true
      description: >-
        This request's ID. Include it when you contact support; it's also
        `request_id` in an error.
      schema:
        type: string
        description: >-
          This request's ID. Include it when you contact support; it's also
          `request_id` in an error.
        example: req_01J9Z8Q4N2K7T5V3X6Y8B0C1D2
    RateLimit-Limit:
      required: true
      description: Requests allowed per window from your client.
      schema:
        type: integer
        minimum: 0
        maximum: 9007199254740991
        description: Requests allowed per window from your client.
        example: 300
    RateLimit-Remaining:
      required: true
      description: Requests left in the current window.
      schema:
        type: integer
        minimum: 0
        maximum: 9007199254740991
        description: Requests left in the current window.
        example: 299
    RateLimit-Reset:
      required: true
      description: Seconds until the window resets.
      schema:
        type: integer
        minimum: 0
        maximum: 9007199254740991
        description: Seconds until the window resets.
        example: 42
    Retry-After:
      required: true
      description: Seconds to wait before you retry.
      schema:
        type: integer
        minimum: 0
        maximum: 9007199254740991
        description: Seconds to wait before you retry.
        example: 42
  responses:
    InvalidParameterOrConflictingCredentials:
      description: '`invalid_parameter`, `conflicting_credentials`'
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimit-Limit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimit-Remaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            invalid_parameter:
              value:
                error:
                  type: invalid_request_error
                  code: invalid_parameter
                  message: Invalid request parameters.
                  param: null
                  doc_url: null
                  request_id: req_8kQ2vX9mR4tL6nB1cW3yZ5aD
            conflicting_credentials:
              value:
                error:
                  type: invalid_request_error
                  code: conflicting_credentials
                  message: Send one API key.
                  param: null
                  doc_url: null
                  request_id: req_8kQ2vX9mR4tL6nB1cW3yZ5aD
    AuthenticationRequired:
      description: '`authentication_required`'
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimit-Limit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimit-Remaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            authentication_required:
              value:
                error:
                  type: authentication_error
                  code: authentication_required
                  message: Authentication is required.
                  param: null
                  doc_url: null
                  request_id: req_8kQ2vX9mR4tL6nB1cW3yZ5aD
    PermissionDenied:
      description: '`permission_denied`'
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimit-Limit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimit-Remaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            permission_denied:
              value:
                error:
                  type: permission_error
                  code: permission_denied
                  message: Permission denied.
                  param: null
                  doc_url: null
                  request_id: req_8kQ2vX9mR4tL6nB1cW3yZ5aD
    Conflict:
      description: '`conflict`'
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimit-Limit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimit-Remaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            conflict:
              value:
                error:
                  type: conflict_error
                  code: conflict
                  message: The request conflicts with the current state.
                  param: null
                  doc_url: null
                  request_id: req_8kQ2vX9mR4tL6nB1cW3yZ5aD
    RateLimitExceeded:
      description: '`rate_limit_exceeded`'
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimit-Limit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimit-Remaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimit-Reset'
        Retry-After:
          $ref: '#/components/headers/Retry-After'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            rate_limit_exceeded:
              value:
                error:
                  type: rate_limit_error
                  code: rate_limit_exceeded
                  message: Too Many Requests
                  param: null
                  doc_url: null
                  request_id: req_8kQ2vX9mR4tL6nB1cW3yZ5aD
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Your workspace API key, `leap_...`. Create one at
        https://app.tryleap.ai/go/api, and keep it on your server.
    Bearer:
      type: http
      scheme: bearer
      description: >-
        The same API key as `Authorization: Bearer leap_...`, the way most HTTP
        clients and coding agents send one. Send one header or the other; two
        different keys are a `400`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.