GEThttps://api.veriko.mx/v1/webhooks

List webhook endpoints

Audience
public
Auth
API key
Permission
webhooks:read
How-to guide →

Returns all webhook endpoints registered by the authenticated user, with their current status (active, disabled) and subscribed events. The signing secret is not exposed here — it appears only once in the POST /v1/webhooks response when the endpoint is created. To verify an endpoint is still reachable use POST /v1/webhooks/{id}/test.

Request
curl -X GET 'https://api.veriko.mx/v1/webhooks' \
  -H 'Authorization: Bearer veriko_••••'

Python example — coming soon.

JavaScript example — coming soon.

PHP example — coming soon.

Response 200WebhookEndpoint — List of the user's webhook endpoints with their status and subscribed events.
FieldTypeDescription
type*string

Resource type, fixed for this operation. Part of the resource identity in the JSON:API envelope. Always webhook_endpoint.

e.g. webhook_endpoint
id*string (uuid)

Endpoint identifier.

e.g. a1b2c3d4-e5f6-7890-abcd-ef0123456789
attributes*object

Canonical webhook endpoint attributes (receiver URL, subscribed events, status, and secret).

urlstring (uri)

HTTPS receiver URL. Production rejects plain HTTP, URLs resolving to private IPs (SSRF), and URLs >2048 chars.

e.g. https://example.com/webhooks/entregas
eventsarray

List of subscribed events. Maximum 10.

descriptionstring | nullnullable

Free-form endpoint label.

e.g. Alta de pagos en el ERP
statusstring

active receives deliveries. disabled was manually paused. auto_disabled was disabled by the platform after exceeding webhooks.auto_disable_threshold consecutive failures.

e.g. active
consecutive_failuresinteger

Consecutive failures counter. Resets on a success.

e.g. 0
last_delivery_atTimestampUTC | null

UTC timestamp of the last delivery attempt (any status). null when the endpoint hasn't received any delivery yet.

secretstring

Shared secret for signature verification. Only present in the create and rotate-secret responses; omitted from every other response.

e.g. whsec_a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6
secret_hintstring

Last 4 chars of the secret prefixed with .... Present on any response where the full secret is hidden.

e.g. ...4f2a
created_atstring (date-time)

ISO 8601 timestamp in UTC with explicit Z suffix. Example: "2026-05-01T05:14:38Z". Every datetime field uses this shape. The descriptor at meta.datetime makes the contract runtime-assertable.

e.g. 2026-05-01T05:14:38Z
updated_atstring (date-time)

ISO 8601 timestamp in UTC with explicit Z suffix. Example: "2026-05-01T05:14:38Z". Every datetime field uses this shape. The descriptor at meta.datetime makes the contract runtime-assertable.

e.g. 2026-05-01T05:14:38Z
Response status codesGET /v1/webhooks
StatusClassDescriptionBody
2002xxList of the user's webhook endpoints with their status and subscribed events.No body
4014xxAuthentication is required or the provided credentials are invalid.ErrorResponse
4034xxInsufficient permissions.ErrorResponse
4294xxRate limit exceededErrorResponse
Errors from GET /v1/webhooks
StatusCodeExample
401unauthorized

Invalid or missing authentication credentials.

Envelope
meta.request_id
c4d5e6f7a8b9
403forbidden

You do not have permission to access this resource.

Envelope
meta.request_id
d5e6f7a8b9c0
429rate_limit_exceeded

Rate limit exceeded. Try again in 45 seconds.

Envelope
meta.request_id
f7a8b9c0d1e2
Response headers
  • Retry-After: integer — Seconds to wait before retrying. Matches the endpoint's rate-limit window (typically 60s for list endpoints, 1-5s for in-flight idempotent operations).
  • X-RateLimit-Limit: integer — Configured request cap for this bucket (emitted only on 429).
  • X-RateLimit-Remaining: integer — Requests remaining in the current window — always 0 at the moment of the 429 (emitted only on 429).
  • X-RateLimit-Reset: integer — Absolute Unix epoch (seconds) when the window resets. Emitted only on 429, alongside Retry-After. Per-endpoint overrides exist (e.g. `rate_limited_login`).