Criar credencial

POST /webhooks/credentials

Request — variante API_KEY

{
  "name": "erp-integration",
  "auth": {
    "type": "API_KEY",
    "headerName": "X-Api-Key",
    "value": "seu-segredo"
  }
}

Request — variante JWT

{
  "name": "erp-integration",
  "auth": {
    "type": "JWT",
    "tokenUrl": "https://partner.example.com/oauth/token",
    "clientId": "client-id",
    "clientSecret": "client-secret"
  }
}
auth.typeCamposComportamento na entrega
API_KEYheaderName, valueA Creditas envia value no header headerName em toda entrega
JWTtokenUrl, clientId, clientSecretA Creditas troca as credenciais por um token (OAuth2 client_credentials) em tokenUrl antes de cada entrega e envia Authorization: Bearer <token>

name é obrigatório e único por parceiro. Não existe uma terceira forma de autenticação
inline — todo webhook referencia uma credencial por id.

Sucesso — 201 Created

{
  "id": "8f14e0a1-2b3c-4d5e-9f01-abcdef123456",
  "name": "erp-integration",
  "authType": "API_KEY",
  "createdAt": "2026-09-16T12:34:56Z",
  "updatedAt": "2026-09-16T12:34:56Z"
}

O segredo nunca é devolvido em nenhuma response. Apenas authType é exposto.