# List webhook endpoints

URL: https://docs.fxapis.com/api-reference/webhooks/list-webhook-endpoints

> List webhook endpoints. Newest first.

`GET https://api.fxapis.com/v1/webhooks`

Newest first. Deleted endpoints are not listed. Secrets are never returned here.

Authentication: `Authorization: Bearer <API key>`.

#### Responses

- `200`
- `401`
- `403`

Failures return `{ "error": { "code", "message" } }`; every code is listed at https://docs.fxapis.com/errors.

#### 200 response fields

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `data` | object[] | no |  |
| `data[].id` | string (uuid) | no |  |
| `data[].url` | string | no | Example: `"https://example.com/fxapis/webhooks"` |
| `data[].description` | null \| string | no | Example: `"Copier"` |
| `data[].events` | "order.filled" \| "order.rejected" \| "order.unresolved" \| "order.resolved" \| "order.cancelled" \| "position.opened" \| "position.closed" \| "account.state_changed" \| "wave.settled"[] | no | The events this endpoint receives. Empty means every event. |
| `data[].enabled` | boolean | no | Whether events are being sent. False when you disabled it, or when we did after 20 failed deliveries in a row — see `disabledReason`. |
| `data[].disabledAt` | null \| string (date-time) | no | When we switched it off for failing. Null when you disabled it yourself. |
| `data[].disabledReason` | null \| string | no | Example: `"20 deliveries in a row failed"` |
| `data[].consecutiveFailures` | integer | no | Failed deliveries since the last success. |
| `data[].secretHint` | null \| string | no | The signing secret's last characters, to tell secrets apart. Example: `"whsec_…Qx4w"` |
| `data[].previousSecretExpiresAt` | null \| string (date-time) | no | After a rotation, deliveries are signed with the old secret too until this time. |
| `data[].createdAt` | string (date-time) | no |  |
| `data[].updatedAt` | string (date-time) | no |  |