Register a new webhook endpoint. The signing secret is returned only in the creation response — store it securely.
API key authentication. Prefix your key with Bearer in the Authorization header.
Keys follow the format qq_... and can be scoped to specific permissions.
Registered webhook (includes secret)