> ## Documentation Index
> Fetch the complete documentation index at: https://docs.secapi.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# GET /v1/webhook_endpoints

> List webhook endpoints for the current organization

List webhook endpoints for the current organization

<Info>
  Audience: application and admin.
</Info>

## Endpoint inventory

The list is scoped to the authenticated organization and returns endpoint configuration, subscribed event types, status, and `lastDeliveredAt`. It never returns a signing secret. Use the endpoint id with delivery-attempt history when diagnosing an event.

## Canonical metadata

* `requestId`
* `traceparent`

## Example request

<RequestExample>
  ```bash theme={null}
  curl -X GET \
    -H "x-api-key: $SECAPI_API_KEY" \
    -H "secapi-version: 2026-03-19" \
    "https://api.secapi.ai/v1/webhook_endpoints"
  ```
</RequestExample>

## Example response

<ResponseExample>
  ```json theme={null}
  {
    "object": "list",
    "data": [
      {
        "object": "webhook_endpoint",
        "id": "wh_2ZK8Q1W9F4M6P7R3",
        "createdAt": "2026-06-25T15:00:00.000Z",
        "updatedAt": "2026-06-25T15:00:00.000Z",
        "livemode": false,
        "orgId": "org_example_123",
        "description": "Production monitor matches",
        "destinationUrl": "https://example.com/hooks/secapi",
        "subscribedEventTypes": [
          "monitor.match",
          "webhook.test"
        ],
        "status": "active",
        "lastDeliveredAt": null
      }
    ],
    "hasMore": false,
    "nextCursor": null,
    "queryPath": null,
    "queryPathReason": null,
    "policyYears": null,
    "degradedState": null,
    "requestId": "req_2ZK8Q1W9F4M6P7R3",
    "traceparent": "00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01"
  }
  ```
</ResponseExample>

## Give this prompt to your agent

<Prompt>
  Call SEC API GET /v1/webhook\_endpoints to list the authenticated organization's destinations, subscribed event types, active state, and last delivery time. The list does not reveal signing secrets.
</Prompt>

## Failure posture

* treat non-2xx responses as contract-aware failures, not free-form errors
* preserve `requestId` and `traceparent` in logs and downstream reports
* if provenance or freshness metadata is present, return it unchanged so trust is not lost in the handoff
