/v1/webhooks/endpointsstableList endpoints
- Needs
- Read your data
(mcp:read) - Plan
- Any plan with API access
- Limits
- 300 a minute per key
- Undo
- Nothing to undo: this only reads.
Lists the URLs that receive your events. Signing secrets are never returned here.
Try it
Query (4)
Only this status.
URL contains this text.
How many items per page (1–100).
The `next_cursor` from the previous page. Cursors expire after 24 hours.
This only reads. It uses your real data and changes nothing.
Code and response
curl -X GET 'https://mcp.wa-api.cloud/v1/webhooks/endpoints' \ -H "Authorization: Bearer $API_KEY"
The code reads your key from $API_KEY.
Parameters
| Field | Type | What it is |
|---|---|---|
| status | string · query | Only this status.one of: active, disabled, paused |
| url_contains | string · query | URL contains this text.1–200 characters |
| limit | integer · query | How many items per page (1–100).1–100 · default 25 |
| cursor | string · query | The next_cursor from the previous page. Cursors expire after 24 hours.1–2048 characters |
Headers
| Field | Type | What it is |
|---|---|---|
| Authorizationrequired | header | Bearer $API_KEY — your API key. |
| Api-Version | header | The API version to use, e.g. 2026-10-01. Default: the version your key is pinned to.one of: 2026-10-01 · pattern ^\d{4}-\d{2}-\d{2}$ |
Response 200
A page of endpoints.
| Field | Type | What it is |
|---|---|---|
| datarequired | array of object | |
| idrequired | string | |
| urlrequired | string | |
| descriptionrequired | string or null | |
| statusrequired | string | active | disabled | paused |
| custom_headersrequired | object | Custom header names; values masked to the last 4 characters. |
| consecutive_failuresrequired | number | |
| disabled_atrequired | string or null | |
| disabled_reasonrequired | string or null | |
| signing_secretrequired | string | Always masked. The secret is shown once, on create or rotate. |
| payload_formatrequired | string | "data" = the event's data object as the body; "envelope" = {id, type, version, api_version, occurred_at, company_id, data}.one of: data, envelope |
| created_atrequired | string or null | |
| updated_atrequired | string or null | |
| subscriptions | object or null | |
| countrequired | number | |
| all_activerequired | boolean | |
| event_typesrequired | array of object | |
| next_cursorrequired | string or null | Pass as "cursor" to get the next page; null when there are no more results. |
Errors
Errors are application/problem+json. Branch on code.
| Status | Code | When |
|---|---|---|
| 400 | invalid_input | A field is missing or has the wrong format. |
| 401 | unauthenticated | The Authorization header is missing, the key is unknown, expired or revoked. |
| 403 | entitlement_required | The workspace's plan does not include API access ( |
| 403 | insufficient_scope | The key does not have the permission this operation needs. |
| 429 | rate_limited | The key or workspace went over its rate limit. Wait for |
| 503 | upstream_unavailable | A service behind the API is briefly unavailable. Safe to retry with backoff. |
Examples
All endpoints
Response 200
{
"data": [
{
"id": "ep_01J8Z6Q4M9W2X7K3B5N1R0T8YA",
"url": "https://hooks.example.com/incoming",
"description": "Order system",
"status": "active",
"custom_headers": {
"X-Hook-Token": "••••9f2a"
},
"payload_format": "envelope",
"consecutive_failures": 0,
"disabled_reason": null,
"signing_secret": "whsec_••••••••",
"created_at": "2026-09-10T12:00:00Z",
"updated_at": "2026-09-10T12:00:00Z",
"disabled_at": null
}
],
"next_cursor": null
}Operation path
The same operation is also at POST /v1/ops/webhooks_list_endpoints, with every field in the JSON body.