Skip to content

Webhooks

List webhooks

Returns the workspace’s webhooks as a JSON array. Secrets and tokens are never included in the list.

GET/api/v1/webhooks
  • Console only: owner or admin
  • Workspace: X-Tenant-ID

Headers

  • Cookiestringrequired

    The whatsappx_session cookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.

    Example
    whatsappx_session=…
  • X-Tenant-IDuuidrequired

    Workspace id. Required for session requests. You can pass ?tenant=<id> instead.

    Example
    8d0f6c2e-3b1a-4c55-9a7e-2f4b6d1e9c30

Response

200 OKapplication/json

  • []array<Webhook>

    Webhooks of the workspace.

    Show child attributesHide child attributes8
    • iduuid

      Webhook id.

    • urlstring

      HTTPS URL that receives deliveries.

    • eventsstring

      Always messages. It is informational and not a filter: every enabled webhook receives every event.

    • enabledboolean

      Whether deliveries are sent.

    • has_tokenboolean

      Whether a shared token is sent in X-Whatsappx-Webhook-Token.

    • created_atinteger

      Creation time in Unix seconds.

    • secretstringmay be absent

      Signing secret (whsec_ + 48 hex characters). Returned only in the create response; store it to verify X-Hub-Signature-256.

    • tokenstringmay be absent

      The shared token, returned only in the response that set or generated it. Generated tokens are whtok_ + 48 hex characters.

Status codes

  • 200OK. An array of webhooks (not wrapped in an object).
  • 401Unauthorized. No signed-in session (unauthorized).
  • 403Forbidden. API keys can never call this endpoint (API keys cannot administer workspaces). A signed-in user who is not an owner or admin gets admin required; a user who is not a member of the workspace gets forbidden.
  • 500Server error. The webhooks could not be loaded.