# List destinations

List outbound webhook destinations.

Returns the tenant webhook endpoints, newest first. A tenant may have at most five destinations. Secrets are never returned here; only secretPrefix is included.

This route is console / Firebase only for now. Tenant API keys are not accepted.

## See also

- [Webhooks](https://www.invunion.com/knowledge-base/api/webhooks/). Events you can subscribe to and the JSON posted to your URL.

- HTTP method: `GET`
- Path: `/api/v1/webhook-endpoints`
- URL: `https://api.invunion.com/api/v1/webhook-endpoints`
- Required scope: `none — Firebase console only`
- HTML docs: https://www.invunion.com/knowledge-base/api/list-webhook-endpoints/
- Markdown docs: https://www.invunion.com/knowledge-base/api/list-webhook-endpoints.md




## Errors

| Error | HTTP code | Description |
| --- | --- | --- |
| `Missing Bearer token` | `401` | The Authorization header is missing or is not a Bearer token. |
| `Invalid token` | `401` | Webhook destinations and deliveries are console-only. Send a Firebase ID token. Tenant API keys are not accepted on these routes. |
| `Too many requests, please try again later` | `429` | Wait and retry. The Retry-After header is the number of seconds to wait. |
| `Tenant context required` | `400` | The authenticated credential is not bound to a tenant. |
| `Internal server error` | `500` | Unexpected server error. The JSON body includes correlationId. Retry with backoff. |

## Request (curl)

```bash
curl --request GET \
  --url https://api.invunion.com/api/v1/webhook-endpoints \
  --header 'accept: application/json' \
  --header 'authorization: Bearer FIREBASE_ID_TOKEN'
```

## Request (Python)

```python
import requests

url = "https://api.invunion.com/api/v1/webhook-endpoints"
headers = {
    "Accept": "application/json",
    "Authorization": "Bearer FIREBASE_ID_TOKEN",
}
response = requests.get(url, headers=headers)
print(response.json())
```

## Request (Ruby)

```ruby
require 'net/http'
require 'json'
require 'uri'

uri = URI("https://api.invunion.com/api/v1/webhook-endpoints")
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Accept'] = 'application/json'
request['Authorization'] = 'Bearer FIREBASE_ID_TOKEN'
response = http.request(request)
puts response.body
```

## Request (JavaScript)

```javascript
const response = await fetch("https://api.invunion.com/api/v1/webhook-endpoints", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": "Bearer FIREBASE_ID_TOKEN"
  },
});
const data = await response.json();
```

## Request (Go)

```go
package main

import (
	"fmt"
	"io"
	"net/http"
)

func main() {
	req, err := http.NewRequest("GET", "https://api.invunion.com/api/v1/webhook-endpoints", nil)
	if err != nil {
		panic(err)
	}
	req.Header.Set("Accept", "application/json")
	req.Header.Set("Authorization", "Bearer FIREBASE_ID_TOKEN")
	resp, err := http.DefaultClient.Do(req)
	if err != nil {
		panic(err)
	}
	defer resp.Body.Close()
	body, _ := io.ReadAll(resp.Body)
	fmt.Println(string(body))
}
```

## Request (Node)

```javascript
const response = await fetch("https://api.invunion.com/api/v1/webhook-endpoints", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": "Bearer FIREBASE_ID_TOKEN"
  },
});
console.log(await response.json());
```

## Success (200)

```json
{
  "success": true,
  "data": [
    {
      "id": "4e2deb4d-3b7d-4bad-9bdd-2b0d7b3dcb6d",
      "url": "https://hooks.leonescars.example/invunion",
      "description": "Leones Cars operations",
      "eventTypes": [
        "invoice.paid",
        "match.created"
      ],
      "secretPrefix": "whsec_4e2d",
      "active": true,
      "consecutiveFailures": 0,
      "lastSuccessAt": "2026-09-12T09:00:04.000Z",
      "lastFailureAt": null,
      "lastDeliveryAt": "2026-09-12T09:00:04.000Z",
      "disabledAt": null,
      "disabledReason": null,
      "createdAt": "2026-09-01T08:00:00.000Z",
      "updatedAt": "2026-09-12T09:00:04.000Z"
    },
    {
      "id": "a0cf4617-6d39-42b4-fd36-43720e50c8f6",
      "url": "https://hooks.grovestreet.example/invunion",
      "description": "Grove Street billing",
      "eventTypes": [
        "invoice.created",
        "invoice.updated"
      ],
      "secretPrefix": "whsec_a0cf",
      "active": true,
      "consecutiveFailures": 0,
      "lastSuccessAt": "2026-09-08T14:22:09.000Z",
      "lastFailureAt": null,
      "lastDeliveryAt": "2026-09-08T14:22:09.000Z",
      "disabledAt": null,
      "disabledReason": null,
      "createdAt": "2026-08-20T10:00:00.000Z",
      "updatedAt": "2026-09-08T14:22:09.000Z"
    }
  ]
}
```
