# Webhook Permission Denied On Create

**URL:** <https://www.patreondevelopers.com/t/webhook-permission-denied-on-create/4282>\
**Category:** Friendly Help\
**Created:** [March 7, 2021, 12:34am UTC](https://www.patreondevelopers.com/t/webhook-permission-denied-on-create/4282 "2021-03-07T00:34:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kyle](https://avatars.discourse-cdn.com/v4/letter/k/848f3c/32.png) [@Kyle](https://www.patreondevelopers.com/u/Kyle)\
**Post date:** [March 7, 2021, 12:34am UTC](https://www.patreondevelopers.com/t/webhook-permission-denied-on-create/4282/1 "2021-03-07T00:34:41Z")

</div>

I’m new to this api and I’m trying to create a webhook for one of the campaigns I’ve pledged to. When I try to create the webhook, I keep getting the following response

```auto
{"errors":[{"code":null,"code_name":"CreateForbidden","detail":"You do not have permission to create this webhook.","status":"403","title":"You do not have permission to create this webhook."}]}

```

Is there some sort of other authentication that I’m missing that I need to do to create the webhook?

This is what my payload looks like:

```auto
payload = {
        "data": {
            "type": "webhook",
            "attributes": {
                "triggers": ["posts:publish"],
                "uri": my_uri,
            },
            "relationships": {
                "campaign": {
                    "data": {"type": "campaign", "id": campaign_id},
                },
            },
        }
    }

```

---

<div class="post-metadata">

**Author:** ![codebard](https://yyz2.discourse-cdn.com/flex036/user_avatar/www.patreondevelopers.com/codebard/32/14_2.png) [@codebard](https://www.patreondevelopers.com/u/codebard)\
**Post date:** [March 10, 2021, 12:32am UTC](https://www.patreondevelopers.com/t/webhook-permission-denied-on-create/4282/2 "2021-03-10T00:32:11Z")

</div>

You can try the call which Patreon WordPress uses. Also you should pay attention to headers which the class sends:

> <https://github.com/Patreon/patreon-wordpress/blob/cacf8f9f3ba4889eb99ff7cddbf93341814ae286/classes/patreon_api_v2.php#L133>

---

<div class="post-metadata">

**Author:** ![Kyle](https://avatars.discourse-cdn.com/v4/letter/k/848f3c/32.png) [@Kyle](https://www.patreondevelopers.com/u/Kyle)\
**Post date:** [March 12, 2021, 5:38pm UTC](https://www.patreondevelopers.com/t/webhook-permission-denied-on-create/4282/3 "2021-03-12T17:38:11Z")

</div>

I seem to be doing exactly the same thing as the patreon wordpress class is doing, although a little bit different because I’m working with python flask. I’m sending in the bearer line in the header but I don’t have the User-Agent line. I did a search and couldn’t find anything useful on it. Could I get an explanation as to what it does?

---

<div class="post-metadata">

**Author:** ![codebard](https://yyz2.discourse-cdn.com/flex036/user_avatar/www.patreondevelopers.com/codebard/32/14_2.png) [@codebard](https://www.patreondevelopers.com/u/codebard)\
**Post date:** [March 15, 2021, 3:30pm UTC](https://www.patreondevelopers.com/t/webhook-permission-denied-on-create/4282/4 "2021-03-15T15:30:47Z")

</div>

Missing user agent header may cause your app to be mistaken for a bot. So, it should be there. It is a (rather arbitrary) name that you yourself give to your app’s api caller to identify it.
