> ## Documentation Index
> Fetch the complete documentation index at: https://t3sa.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Register webhook destination

> Draft: specification in progress. Endpoints and fields may change.

Registers a webhook destination. The secret used to verify the signature
is shown only once, in this response. Scope: `admin`.


<Warning>Draft: specification in progress. Endpoints and fields may change.</Warning>


## OpenAPI

````yaml /en/api/openapi.yaml post /webhooks
openapi: 3.1.0
info:
  title: TESA API
  version: 0.1.0-rascunho
  description: >
    **Draft: specification in progress. Endpoints and fields may change.**


    TESA's B2B treasury infrastructure API. USDC comes in through Circle's CCTP

    (Ethereum and Solana) and is allocated to tokenized Treasuries (USDY and
    BUIDL).

    The API is non-custodial: it never receives a private key or a signed
    transaction.

    It returns unsigned transactions and approval requests, and the signer is
    the

    company or its custodian.


    Resource paths, field names, event names and error codes are in Portuguese
    by

    design. Amounts are USDC decimal strings with two decimal places, dates are
    ISO

    8601 UTC and lists use cursor pagination (`limite` and `apos`). All example

    values are illustrative.
  contact:
    name: TESA
    email: contact@t3sa.com
    url: https://t3sa.com
servers:
  - url: https://api.t3sa.com/v1
    description: Production (proposed URL, not live yet)
  - url: https://sandbox.api.t3sa.com/v1
    description: Sandbox (proposed URL, not live yet)
security:
  - bearerAuth: []
tags:
  - name: Organization
    description: The client company, owner of all keys and resources.
  - name: Wallets
    description: >-
      Company wallets linked by public address. No key ever passes through the
      API.
  - name: Positions
    description: A snapshot of the cash position, the same as in the dashboard.
  - name: Allocation policy
    description: Assets approved by the company and the proportion between them.
  - name: Proposals
    description: >-
      Every allocation movement starts as a proposal and only executes with
      approval.
  - name: Redemptions
    description: Return of USDC balance to a linked company wallet.
  - name: Records
    description: On-chain audit trail, with the hash of each transaction.
  - name: Yield and charges
    description: Yield calculated per period and the fee charged on it.
  - name: Webhooks
    description: Destinations that receive TESA events.
paths:
  /webhooks:
    post:
      tags:
        - Webhooks
      summary: Register webhook destination
      description: |
        Draft: specification in progress. Endpoints and fields may change.

        Registers a webhook destination. The secret used to verify the signature
        is shown only once, in this response. Scope: `admin`.
      operationId: criarWebhook
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WebhookCriar'
      responses:
        '201':
          description: Destination registered.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Webhook'
                  - type: object
                    properties:
                      segredo:
                        type: string
                        description: The destination's HMAC secret. Shown only at creation.
                        examples:
                          - whsec_...
        '400':
          $ref: '#/components/responses/RequisicaoInvalida'
        '401':
          $ref: '#/components/responses/NaoAutenticado'
        '403':
          $ref: '#/components/responses/SemPermissao'
      security:
        - bearerAuth: []
        - bearerAuth: []
          tesaTimestamp: []
          tesaSignature: []
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      description: >-
        Unique value generated by the integration. Repeating the key with the
        same body returns the original response.
      schema:
        type: string
        format: uuid
  schemas:
    WebhookCriar:
      type: object
      required:
        - url
      properties:
        url:
          type: string
          format: uri
        eventos:
          type: array
          items:
            $ref: '#/components/schemas/EventoWebhook'
    Webhook:
      type: object
      properties:
        id:
          type: string
          examples:
            - wh_6r3n
        url:
          type: string
          format: uri
        eventos:
          type: array
          description: An empty list subscribes to all events.
          items:
            $ref: '#/components/schemas/EventoWebhook'
        status:
          type: string
          enum:
            - ativo
            - pausado
        criado_em:
          type: string
          format: date-time
    EventoWebhook:
      type: string
      enum:
        - deposito.confirmado
        - alocacao.proposta
        - alocacao.aprovada
        - resgate.concluido
        - rendimento.apurado
        - cobranca.emitida
    Erro:
      type: object
      properties:
        erro:
          type: object
          properties:
            codigo:
              type: string
              examples:
                - saldo_insuficiente
            mensagem:
              type: string
            campo:
              type:
                - string
                - 'null'
            requisicao_id:
              type: string
              examples:
                - req_9d8c7b
  responses:
    RequisicaoInvalida:
      description: Malformed body or missing parameter (`requisicao_invalida`).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Erro'
    NaoAutenticado:
      description: Missing, invalid or revoked key, or invalid HMAC signature.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Erro'
    SemPermissao:
      description: Insufficient scope or IP outside the allowlist.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Erro'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        The organization's API key (`tesa_live_...` in production,
        `tesa_test_...` in the sandbox).
    tesaTimestamp:
      type: apiKey
      in: header
      name: Tesa-Timestamp
      description: >-
        Optional in the current proposal. Request time in Unix seconds, used in
        the HMAC signature.
    tesaSignature:
      type: apiKey
      in: header
      name: Tesa-Signature
      description: >-
        Optional in the current proposal. Hex-encoded HMAC-SHA256 of the
        canonical message (timestamp, method, path and raw body).

````