Webhooks
List webhooks
Returns the workspace’s webhooks as a JSON array. Secrets and tokens are never included in the list.
- Console only: owner or admin
- Workspace:
X-Tenant-ID
Headers
CookiestringrequiredThe
whatsappx_sessioncookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.X-Tenant-IDuuidrequiredWorkspace id. Required for session requests. You can pass
?tenant=<id>instead.
Response
200 OKapplication/json
[]array<Webhook>Webhooks of the workspace.
Show child attributesHide child attributes8
iduuidWebhook id.
urlstringHTTPS URL that receives deliveries.
eventsstringAlways
messages. It is informational and not a filter: every enabled webhook receives every event.enabledbooleanWhether deliveries are sent.
has_tokenbooleanWhether a shared token is sent in
X-Whatsappx-Webhook-Token.created_atintegerCreation time in Unix seconds.
secretstringmay be absentSigning secret (
whsec_+ 48 hex characters). Returned only in the create response; store it to verifyX-Hub-Signature-256.tokenstringmay be absentThe shared token, returned only in the response that set or generated it. Generated tokens are
whtok_+ 48 hex characters.
Status codes
- 200OK. An array of webhooks (not wrapped in an object).
- 401Unauthorized. No signed-in session (
unauthorized). - 403Forbidden. API keys can never call this endpoint (
API keys cannot administer workspaces). A signed-in user who is not an owner or admin getsadmin required; a user who is not a member of the workspace getsforbidden. - 500Server error. The webhooks could not be loaded.