curl --request GET \
--url https://api.webhook.co/v1/endpoints/{endpointId}/events \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.webhook.co/v1/endpoints/{endpointId}/events', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.webhook.co/v1/endpoints/{endpointId}/events"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.webhook.co/v1/endpoints/{endpointId}/events"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"items": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"endpointId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"receivedAt": "2023-11-07T05:31:56Z",
"provider": "stripe",
"dedupKey": "<string>",
"dedupStrategy": "sw_webhook_id",
"verified": true,
"verificationState": "verified"
}
],
"nextCursor": "<string>",
"headCursor": "<string>"
}{
"error": "<string>",
"message": "<string>"
}{
"error": "<string>",
"message": "<string>"
}{
"error": "<string>",
"message": "<string>"
}"<string>"List captured events for an endpoint (deprecated, use the org-wide events list)
curl --request GET \
--url https://api.webhook.co/v1/endpoints/{endpointId}/events \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.webhook.co/v1/endpoints/{endpointId}/events', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.webhook.co/v1/endpoints/{endpointId}/events"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.webhook.co/v1/endpoints/{endpointId}/events"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"items": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"endpointId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"receivedAt": "2023-11-07T05:31:56Z",
"provider": "stripe",
"dedupKey": "<string>",
"dedupStrategy": "sw_webhook_id",
"verified": true,
"verificationState": "verified"
}
],
"nextCursor": "<string>",
"headCursor": "<string>"
}{
"error": "<string>",
"message": "<string>"
}{
"error": "<string>",
"message": "<string>"
}{
"error": "<string>",
"message": "<string>"
}"<string>"Authorizations
A whk_-prefixed API key (opaque; not a JWT).
Path Parameters
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Query Parameters
Opaque keyset cursor from a prior page's nextCursor.
Max items to return (1–200, default 50).
x <= 200Filter by provider (repeatable).
stripe, github, shopify, slack, standard_webhooks, clerk, resend, stytch, supabase, render, brex, openai, replicate, polar, gemini, incident_io, etsy, vanta, pusher, quickbooks, chargify, launchdarkly, modern_treasury, autodesk_aps, mongodb_atlas, xero, segment, aftership, onfleet, webflow, klaviyo, mux, shippo, buildkite, ms_teams, ably, squarespace, nylas, linkedin, tiktok, airship, lob, persona, bolt, primer, airwallex, affirm, keygen, constant_contact, telegram, mixpanel, new_relic, fillout, zapier, tally, loops, customer_io, framer, box, configcat, ashby, merge_dev, cronofy, increase, finch, knock, deel, razorpay, sentry, linear, dropbox, checkout_com, lemon_squeezy, coinbase_commerce, dwolla, gocardless, notion, meta, woocommerce, bitbucket, atlassian_jira, x, clickup, npm, heroku, dub, cal_com, asana, circleci, pagerduty, airtable, calendly, zoom, sinch, workos, front, zendesk, twitch, paddle, recurly, docusign, vercel, intercom, paystack, authorize_net, sanity, square, trello, twilio, mandrill, hubspot, adyen, mailgun, mercado_pago, braintree, contentful, plivo, typeform, messagebird, netlify, vonage, monday, jira_connect, discord, telnyx, sendgrid, wise, kinde, paypal, aws_sns, plaid, ebay, gitlab, microsoft_graph, chargebee, postmark, sparkpost, okta, bigcommerce, datadog, brevo, checkr, doppler, sendbird Filter by verification state: verified | authenticated | failed | unattempted (repeatable).
verified, authenticated, failed, unattempted Inclusive lower bound: an RFC 3339 instant, a relative duration (7d / 30m — the last N), or beginning.
Exclusive upper bound (RFC 3339 instant).
Case-insensitive substring (min 3 chars) across providerEventId + dedupKey, or an exact event id.
3 - 256Filter by dedup strategy: sw_webhook_id | provider_event_id | content_hash | fields | unique (repeatable).
sw_webhook_id, provider_event_id, content_hash, fields, unique Filter by captured HTTP method: GET | POST | PUT | PATCH | DELETE | HEAD | OPTIONS (repeatable).
GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS Exact match on the normalized, provider-derived event type (e.g. charge.succeeded). Events with no parsed type (providers we don't extract one for) match no eventType value.
1 - 256Case-insensitive substring match over request header names and values (matches a single name OR a single value — NOT a wire-form Name: Value line). A SEPARATE, deliberately-unindexed residual scan — SLOWER than search (which is trigram-indexed), so best combined with a date range. AND-composes with search; never OR'd into it.
1 - 256Was this page helpful?