# GET /v1/webhooks

List the webhooks

Takes a server key (`sk_…`, or `sk_test_…` on a test server) as a bearer token. TypeScript: `sendora.webhooks.list()`. Python: `sendora.webhooks.list()`.

## Responses

### 200 Every webhook of the server.

- `webhooks` (array of object, required)
  - `webhookId` (string (uuid), required)
  - `url` (string, required): Where the events are posted.
  - `events` (array of "delivered" | "bounced" | "deferred" | "spam_complaint" | "unsubscribed" | "cap_warning" | "cap_reached" | "inbound", required)
  - `streamId` (string (uuid) or null, required): The one stream whose message events it receives; null for every stream.
  - `enabled` (boolean, required): False while switched off in the dashboard; nothing is queued for it then.
  - `inboundContent` ("full" | "reference", required): How the inbound event carries a received message: the parsed message, or a reference.
  - `createdAt` (string (date-time), required)
  - `secrets` (array of object, required): The live secrets, oldest first; every delivery is signed with each of them, the newest first in Sendora-Signature.
    - `secretId` (string (uuid), required)
    - `createdAt` (string (date-time), required)

Example:

```json
{
  "webhooks": [
    {
      "webhookId": "7c1e4d2a-0b9f-4a3e-8d6c-5e2f1a9b8c70",
      "url": "https://example.se/hooks/sendora",
      "events": [
        "delivered",
        "bounced",
        "spam_complaint"
      ],
      "streamId": null,
      "enabled": true,
      "inboundContent": "full",
      "createdAt": "2026-09-15T12:00:00.000Z",
      "secrets": [
        {
          "secretId": "4a5b6c7d-8e9f-4a0b-8c1d-2e3f4a5b6c7d",
          "createdAt": "2026-09-15T12:00:00.000Z"
        }
      ]
    }
  ]
}
```

## Errors

Every error answers `error`, the code, and `message`, a sentence for a person. A code that adds fields is shown in full below the table.

| Code | Status | Meaning |
| --- | --- | --- |
| `unauthorized` | 401 | The key is missing, malformed or revoked. |
| `wrong_token_kind` | 403 | The key is of the other kind: a server key (sk_) where an account key (ak_) is needed, or the reverse. The message names the kind the operation takes. |
