Version
READ

list_webhook_endpoints

List outbound webhook endpoints registered for the caller's team. Optional project_id filter, optional active_only filter. Secrets are never returned.

List outbound webhook endpoints registered for the caller's team. Optionally scoped to a single project, or filtered to active endpoints only. Useful for sanity-checking integrations after a suspected outage.

Endpoint secrets are never returned by this tool. They are surfaced only at the moment of creation or rotation via the dashboard or the rotate-secret REST endpoint.

The token behind the MCP session must hold it, or the call is refused with TOKEN_MISSING_ABILITY.

Runs the same action as

The REST endpoint and this tool share one action, so validation, permissions and events are identical.

Annotations

Read-only

It reads and never changes anything.

Arguments

project_idstringoptional

Optional project UUID. Omit to list team-wide endpoints and all project-scoped endpoints within the team.

active_onlybooleanoptional

When true, hides endpoints with is_active=false or disabled_at set.

What it returns

{  "data": [    {      "id": "c62a08f4-1b7d-4e35-9860-a37f5d21e0b9",      "name": "Zapier trigger",      "url": "https://hooks.zapier.com/...",      "project_id": "7f3d1c92-8b45-4e6a-9d21-5c8e0a4b6f13",      "events": ["subscription.created", "payment.succeeded"],      "is_active": true,      "disabled_at": null,      "allowed_ips": null,      "failure_count": 0,      "consecutive_failures": 0,      "last_success_at": "2026-05-18T10:05:00Z",      "last_failure_at": null,      "created_at": "2026-04-01T10:05:00Z"    }  ],  "meta": { "total": 3 }}

How it fails

TOKEN_MISSING_ABILITY

token lacks webhook-endpoint:manage.

How is this guide?

Last updated on