Retrieve a webhook

View as Markdown
Returns one webhook with its configuration, failure counters and last 25 delivery attempts. The signing secret is masked as `"[configured]"`. Custom `headers` are returned in plaintext. Use it to check whether a webhook was disabled automatically: `is_active: false` together with `failure_count: 10`. `last_error` shows the most recent failure. **Idempotency.** A read with no side effects. Safe to retry. **Access** - **Required scope:** `read` or `write`. Any workspace role can call it. - **Rate limit:** General API — 120 requests/min per workspace on Starter or with no active plan, 200 on Growth, 300 on Business, 600 on Enterprise. See [Rate limits](/rate-limits). - **Plan:** Requires the `webhook` plan feature. Every plan includes it today, so this gate currently refuses nobody.

Authentication

AuthorizationBearer
Workspace API key: `jl_` followed by 64 lowercase hex characters, created by the workspace owner in the dashboard (**Settings → API Keys**) and sent as `Authorization: Bearer jl_...`. The plaintext is shown once, at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys. | Scope | GET / HEAD | POST / PUT / PATCH / DELETE | Admin-only routes | | --- | --- | --- | --- | | `read` | Yes | No | No | | `write` | Yes | Yes | No | | `full` | Yes | Yes | Yes | Operations restricted to admins or owners reject keys without the `full` scope with `403`, and say so in their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret — that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds. See [Authentication](/authentication).

Path parameters

webhookIdstringRequiredformat: "uuid"

UUID of the outbound webhook. It must belong to the authenticated workspace; an id from another workspace answers 404, exactly like an unknown one. Returned as id by GET /api/webhooks.

Response

The webhook.
dataobject

An outbound webhook exactly as the API serializes it: the stored row with snake_case keys. secret is masked as "[configured]" on list, retrieve and update. The plaintext signing secret is returned only once, in the POST /api/webhooks response, and a new one by rotate-secret. Custom headers are returned as stored, in plaintext.

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
429
Too Many Requests Error