List webhook subscriptions
Lists all webhook subscriptions configured for the current tenant.
Authentication
AuthorizationBearer
Bearer authentication of the form Bearer <token>, where token is your auth token.
Headers
X-Tenant-Id
Tenant context used for authorization and routing.
X-Request-Timestamp
Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).
X-Content-SHA256
Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.
X-Request-Signature
Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.
Response
List of webhook subscriptions.
subscriptionId
Unique subscription identifier.
tenantId
Tenant that owns this subscription.
url
URL that receives webhook events.
active
Whether the subscription is active.
eventTypes
Event types this subscription receives.
authType
Authentication applied to delivery.
hmacSecretSet
Whether an HMAC key is stored. The key itself is never returned by any endpoint.
createdAt
updatedAt
accountId
Account this subscription is bound to. null means tenant-wide: it receives every account’s events.
Errors
401
Unauthorized Error
403
Forbidden Error
500
Internal Server Error