List webhooks
Authentication
Response
Webhooks ordered by created_at descending. Empty array when there are none.
Webhooks ordered by created_at descending. Empty array when there are none.
Returns the workspace’s outbound webhooks, newest first, including disabled ones. Deleted webhooks are not returned. The list is not paginated and holds at most 100 webhooks.
Each object is the full webhook, including filters, custom headers (in plaintext) and the last
25 delivery attempts in delivery_logs. The signing secret is always masked as "[configured]".
To look at one webhook, use GET /api/webhooks/{webhookId}.
Idempotency. A read with no side effects. Safe to retry.
Access
read or write. Any workspace role can call it.webhook plan feature. Every plan includes it today, including workspaces without an active plan, so this gate currently refuses nobody.Workspace API key: jl_ followed by 64 lowercase hex characters, created by the workspace owner in the
dashboard (Settings → API Keys) and sent as Authorization: Bearer jl_.... The plaintext is shown once,
at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys.
Operations restricted to admins or owners reject keys without the full scope with 403, and say so in
their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret —
that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds.
See Authentication.