https://api.veriko.mx/v1/webhooksList webhook endpoints
How-to guide →Returns all webhook endpoints registered by the authenticated user, with their current status (active, disabled) and subscribed events. The signing secret is not exposed here — it appears only once in the POST /v1/webhooks response when the endpoint is created. To verify an endpoint is still reachable use POST /v1/webhooks/{id}/test.
curl -X GET 'https://api.veriko.mx/v1/webhooks' \
-H 'Authorization: Bearer veriko_••••'Python example — coming soon.
JavaScript example — coming soon.
PHP example — coming soon.
| Field | Type | Description |
|---|---|---|
type* | string | Resource type, fixed for this operation. Part of the resource identity in the JSON:API envelope. Always webhook_endpoint |
id* | string (uuid) | Endpoint identifier. e.g.a1b2c3d4-e5f6-7890-abcd-ef0123456789 |
attributes* | object | Canonical webhook endpoint attributes (receiver URL, subscribed events, status, and secret). |
url | string (uri) | HTTPS receiver URL. Production rejects plain HTTP, URLs resolving to private IPs (SSRF), and URLs https://example.com/webhooks/entregas |
events | array | List of subscribed events. Maximum 10. |
description | string | nullnullable | Free-form endpoint label. e.g.Alta de pagos en el ERP |
status | string |
active |
consecutive_failures | integer | Consecutive failures counter. Resets on a success. e.g.0 |
last_delivery_at | TimestampUTC | null | UTC timestamp of the last delivery attempt (any status). |
secret | string | Shared secret for signature verification. Only present in the create and rotate-secret responses; omitted from every other response. e.g.whsec_a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 |
secret_hint | string | Last 4 chars of the secret prefixed with ...4f2a |
created_at | string (date-time) | ISO 8601 timestamp in UTC with explicit 2026-05-01T05:14:38Z |
updated_at | string (date-time) | ISO 8601 timestamp in UTC with explicit 2026-05-01T05:14:38Z |
| Status | Class | Description | Body |
|---|---|---|---|
| 200 | 2xx | List of the user's webhook endpoints with their status and subscribed events. | No body |
| 401 | 4xx | Authentication is required or the provided credentials are invalid. | ErrorResponse |
| 403 | 4xx | Insufficient permissions. | ErrorResponse |
| 429 | 4xx | Rate limit exceeded | ErrorResponse |
| Status | Code | Example |
|---|---|---|
| 401 | unauthorized | Invalid or missing authentication credentials. Envelope
|
| 403 | forbidden | You do not have permission to access this resource. Envelope
|
| 429 | rate_limit_exceeded | Rate limit exceeded. Try again in 45 seconds. Envelope
Response headers
|