Skip to content
API PlatformDevelopers
GET/v1/webhooks/endpointsstable

List endpoints

Needs
Read your data (mcp:read)
Plan
Any plan with API access
Limits
300 a minute per key
Undo
Nothing to undo: this only reads.

Lists the URLs that receive your events. Signing secrets are never returned here.

Try it

Query (4)

Only this status.

URL contains this text.

How many items per page (1–100).

The `next_cursor` from the previous page. Cursors expire after 24 hours.

This only reads. It uses your real data and changes nothing.

Code and response

curl -X GET 'https://mcp.wa-api.cloud/v1/webhooks/endpoints' \
  -H "Authorization: Bearer $API_KEY"

The code reads your key from $API_KEY.

Parameters

Parameters
FieldTypeWhat it is
statusstring · queryOnly this status.one of: active, disabled, paused
url_containsstring · queryURL contains this text.1–200 characters
limitinteger · queryHow many items per page (1–100).1–100 · default 25
cursorstring · queryThe next_cursor from the previous page. Cursors expire after 24 hours.1–2048 characters

Headers

Headers
FieldTypeWhat it is
AuthorizationrequiredheaderBearer $API_KEY — your API key.
Api-VersionheaderThe API version to use, e.g. 2026-10-01. Default: the version your key is pinned to.one of: 2026-10-01 · pattern ^\d{4}-\d{2}-\d{2}$

Response 200

A page of endpoints.

Response fields
FieldTypeWhat it is
datarequiredarray of object
idrequiredstring
urlrequiredstring
descriptionrequiredstring or null
statusrequiredstringactive | disabled | paused
custom_headersrequiredobjectCustom header names; values masked to the last 4 characters.
consecutive_failuresrequirednumber
disabled_atrequiredstring or null
disabled_reasonrequiredstring or null
signing_secretrequiredstringAlways masked. The secret is shown once, on create or rotate.
payload_formatrequiredstring"data" = the event's data object as the body; "envelope" = {id, type, version, api_version, occurred_at, company_id, data}.one of: data, envelope
created_atrequiredstring or null
updated_atrequiredstring or null
subscriptionsobject or null
countrequirednumber
all_activerequiredboolean
event_typesrequiredarray of object
next_cursorrequiredstring or nullPass as "cursor" to get the next page; null when there are no more results.

Errors

Errors are application/problem+json. Branch on code.

StatusCodeWhen
400invalid_input

A field is missing or has the wrong format. errors[] points at each field.

401unauthenticated

The Authorization header is missing, the key is unknown, expired or revoked.

403entitlement_required

The workspace's plan does not include API access (api_access).

403insufficient_scope

The key does not have the permission this operation needs.

429rate_limited

The key or workspace went over its rate limit. Wait for Retry-After seconds.

503upstream_unavailable

A service behind the API is briefly unavailable. Safe to retry with backoff.

Examples

All endpoints

Response 200

{
  "data": [
    {
      "id": "ep_01J8Z6Q4M9W2X7K3B5N1R0T8YA",
      "url": "https://hooks.example.com/incoming",
      "description": "Order system",
      "status": "active",
      "custom_headers": {
        "X-Hook-Token": "••••9f2a"
      },
      "payload_format": "envelope",
      "consecutive_failures": 0,
      "disabled_reason": null,
      "signing_secret": "whsec_••••••••",
      "created_at": "2026-09-10T12:00:00Z",
      "updated_at": "2026-09-10T12:00:00Z",
      "disabled_at": null
    }
  ],
  "next_cursor": null
}

Operation path

The same operation is also at POST /v1/ops/webhooks_list_endpoints, with every field in the JSON body.