Opens a listen session for the caller's merchant and returns its signing secret, once.
POST
/api/notifications/listen-sessions
deprecated
Requires: Notifications.ListenSessions.Listen, merchant scope.
The secret is not recoverable afterwards: only a hash of it is stored. Losing it means opening a new session.
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a CreateListenSessionInput. See the Request body section below for its fields.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
suppressNulls
required |
query | boolean | If true, omit properties with null values. |
Request body
application/json
, required
| Field | Type | Description |
|---|---|---|
eventTypes
required |
array of string | Event types to stage. Empty means every event type the caller may see, resolved once at creation and then fixed for the session's lifetime. nullable |
label
required |
string | Optional human label, so an operator's list reads sensibly. nullablemax length 128 |
ttlMinutes
required |
integer (int32) | Requested session lifetime in minutes, renewed by poll activity. Clamped server-side; a value outside the supported range is corrected, not refused. nullable |
This request body has no documented fields.
Responses
200 The session was opened. The body carries the signing secret, once.
Body: ListenSessionCreatedDto
Each item has these fields.
| Field | Type | Description |
|---|---|---|
id
required |
string (uuid) | The session id, used on the poll, sample and end routes. |
signingSecret
required |
string | The signing secret, shown exactly once. nullable |
merchantId
required |
string (uuid) | The merchant the session is scoped to. |
eventTypes
required |
array of string | The resolved event types the session stages. nullable |
expiresAtUtc
required |
string (date-time) | When the session expires unless polling renews it. |
ttlMinutes
required |
integer (int32) | The clamped session lifetime, in minutes, that each poll renews by. |
This response has no documented body fields.
403 The caller has no merchant context, so there is no single merchant to scope a session to.
Body:
Each item has these fields.
| Field | Type | Description |
|---|
This response has no body.
default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.
Body: RateLimitProblemDetails
Each item has these fields.
| Field | Type | Description |
|---|---|---|
type
required |
string | The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable |
title
required |
string | A short, human-readable summary of the problem type. nullable |
status
required |
integer (int32) | The HTTP status code, repeated in the body as the problem-details format defines. |
detail
required |
string | A human-readable explanation of this occurrence of the problem. nullable |
retryAfterSeconds
required |
integer (int32) | How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again. |
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.