Admin Portal
API clients and webhooks
Let your applications read entitlements and receive events.
Both pages are under Partner settings › Integrations and need the Integration manager role. The developer side is in Getting started and Verifying webhooks.
API clients
An API client is one of your applications. Open API clients and choose Add API client: a name, the products it may ask about (all, or a selection), its scopes (Entitlements: read, Catalogue: read, Metered usage: write) and an optional rate limit per minute.
On the client's page, add its credentials:
- Add Entra application (preferred): the application (client) id and the tenant its tokens are issued in. The credential stays pending until your application proves control by calling the verification endpoint with the one-time challenge shown (valid 24 hours; New challenge replaces it).
- Create API key: the key is shown once; copy it into your secret store. Rotate issues a new key and keeps the old one valid for an overlap (24 hours by default); Revoke stops a key at once.
Disable stops every credential of the client at once; a disabled client can be deleted.
Webhooks
Open Webhooks and choose Add endpoint:
- Pick the API client, enter the Endpoint URL (
https, a public host name) and an optional description. - Tick the events to receive: subscriptions, seats, customers. An endpoint receives events for its API client's products.
- Save, and copy the signing secret shown once; your receiver uses it to verify every message.
On the endpoint's page:
- Send test event delivers a
webhook.testmessage and shows the response. - The delivery log keeps every message and attempt for 30 days. Replay sends one again (same
webhook-id); Replay failed deliveries re-queues the failures of a period. - Rotate signing secret: for the overlap (24 hours by default) messages carry both signatures, so you can update your receiver without missing events.
- An endpoint that fails for 5 days is turned off automatically and you are emailed. Fix the receiver, send a test event, then Enable it again.
A client can have up to 10 endpoints.