---
updatedAt: 2026-09-30T17:50:34.235Z
---

Fetch the complete documentation index at: https://docs.avvio.xyz/llms.txt. Use this file to discover all available pages before exploring further. Append .md to any documentation page URL to get its markdown version.

# List webhook endpoints

`GET https://api.avvio.xyz/business/api/v1/organizations/{organizationId}/webhook-endpoints`

Lists the webhook endpoints registered for your organization.

Read-only. Registering, pausing, deleting, rotating the secret of or
replaying an endpoint is a dashboard action and cannot be done with an
API key, because a credential that could repoint its own webhook URL could
quietly redirect every payout notification you receive. The dashboard
routes, for completeness: `POST .../webhook-endpoints/{endpointId}/rotate-secret`
(the old secret keeps signing beside the new one for 24 hours, so
nothing in flight drops) and `POST .../webhook-endpoints/{endpointId}/deliveries/replay`
(re-fires up to 1,000 dead deliveries in a `from`/`to` window under
their original event ids, so your dedupe still holds).

The health fields are how you see an endpoint dying without asking us:
`consecutiveFailures` counts exhausted retry ladders since the last
success, and after three of them with no success for five days we
disable the endpoint (`disabledReason: auto_disabled_after_failures`),
email your organization's owners, and deliver
`webhook_endpoint.disabled` to your other endpoints whose `events` list
is empty. It cannot be named in `events`, so an endpoint with an
explicit list never receives it.

The signing secret is never returned here. You are shown it once, when
the endpoint is created or rotated.

## Parameters

- `organizationId` (path, required) — Your organization id.

## Example

```bash
curl -s "$AVVIO_BASE_URL/organizations/$organizationId/webhook-endpoints" \
  -H "x-api-key: $AVVIO_API_KEY"
```

## Responses

- `200` — Registered endpoints
- `401` — The key was refused. Nothing ran. - `UNAUTHORIZED`: missing, invalid or revoked, or a key on a route that does not accept one. - `KEY_EXPIRED`: the key passed the expiry it was issued with. Issue a new one; an expired key cannot be rotated. - `KEY_IP_NOT_ALLOWED`: the key is pinned to source addresses and this request came from another.
- `403` — A valid key that may not make this call. Nothing ran. - `FORBIDDEN`: the key belongs to a different organization. - `ACCOUNT_BLOCKED`: API access for your organization is suspended. - `DEVELOPER_FEATURE_DISABLED`: developer tools (webhook endpoints) are off for your organization. `GET /policy` lists `developer` in `features` when they are on.
- `429` — Too many requests. The default ceiling is **100 requests per minute per API credential** on a 60-second window. High-volume payout and reconciliation routes declare a 600/minute override, and batch submission a 30/minute ceiling. A separate 2,000/minute per-source-IP abuse ceiling always applies. Obey `Retry-After`; it is in seconds and is authoritative. A 429 means the request was refused before the handler ran. Retry reads normally; retry an idempotent mutation with its same `Idempotency-Key`.

Machine contract: [partner-payouts.openapi.yaml](/partner-payouts.openapi.yaml), operation `listWebhookEndpoints`.
