# GET /v1/webhooks

**Service:** Webhooks  
**Operation:** `WebhookService_ListWebhooks`

Sorted by creation time, newest first. Secrets are never included.

## Parameters

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `pageSize` | query | integer | no | The maximum number of subscriptions to return in one page. Optional; a server default applies when unset. |
| `pageToken` | query | string | no | Opaque page token from a previous response, used to fetch the next page. |
| `fields` | query | string | no | Comma-separated response fields to include, using camelCase JSON names (e.g. `orderId,total.amountMicros`). Dot paths reach into nested objects and map transparently across arrays. Paths are relative to the resource, not the response envelope; envelope keys like `nextPageToken` are always preserved. Only 2xx JSON responses are filtered; error bodies pass through unmodified. Unknown names are silently ignored. Takes precedence over `excludeFields` when both are provided. |
| `excludeFields` | query | string | no | Comma-separated response fields to exclude, using camelCase JSON names. Dot paths and array-transparency work the same as `fields`. Paths are relative to the resource, not the response envelope. Only 2xx JSON responses are filtered; error bodies pass through unmodified. Ignored when `fields` is also provided. |

## Responses

| Status | Schema | Description |
| --- | --- | --- |
| 200 | `ListWebhooksResponse` | A successful response. |
| 400 | `Error` | The request was rejected because it was malformed — for example an unusable page token. The body is a validation-failure envelope: an overall type and message and one entry per problem (each with a stable code, a message, and a param pointing at the offending parameter). |
| 401 | `Error` | The request is missing a valid bearer token, or the token is invalid or expired. |
| 403 | `Error` | The token is valid but does not permit this action, or the resource belongs to a company the token cannot act for. The error type is permission_denied. |
| 429 | `Error` | The request was throttled (rate_limited) or exceeded a size limit (resource_exhausted). When throttled, the Retry-After header says how many seconds to wait before retrying; a resource_exhausted request will fail the same way if retried unchanged. |
| default | `Error` | Any other error. The body is the same error envelope every error uses: a short stable type identifying the kind of failure, a human-readable message, and the request's idempotency key echoed back when one was supplied. |

## Returns

`ListWebhooksResponse`

| Field | Type | Description |
| --- | --- | --- |
| `webhooks` | Webhook[] | One page of subscriptions, newest first. Secrets are never included. |
| `webhooks.webhookId` | string | The subscription's id. Read-only. |
| `webhooks.url` | string | The HTTPS endpoint deliveries are POSTed to. Plain http URLs and endpoints resolving to private address space are rejected at create and update time. |
| `webhooks.eventTypes` | string[] | The event types this subscription receives. At least one. Valid values are the v1 taxonomy: `order.created`, `order.updated`, `order.status_changed`, `order.archived`, `quote.created`, `quote.updated`, `quote.status_changed`, `quote.converted_to_order`. Unknown values are rejected naming the offender. |
| `webhooks.status` | WebhookStatus | Whether the subscription is receiving deliveries. New subscriptions are enabled; see WebhookStatus for how a subscription becomes disabled. The lifecycle state of a webhook subscription.   - WEBHOOK_STATUS_ENABLED: The subscription receives deliveries.  - WEBHOOK_STATUS_DISABLED: The subscription receives no deliveries. Set manually via UpdateWebhook, or automatically when deliveries exhaust their retries and nothing has been delivered successfully for 7 days (auto-disable; re-enable via UpdateWebhook once the endpoint is healthy). One of: WEBHOOK_STATUS_UNSPECIFIED, WEBHOOK_STATUS_ENABLED, WEBHOOK_STATUS_DISABLED. |
| `webhooks.description` | string | A free-form label for your own bookkeeping. |
| `webhooks.secret` | string | The signing secret, in the form `whsec_<43 base64url characters>`. Returned ONLY in the CreateWebhook response — store it then; it cannot be retrieved again (rotation is not available in v1). The FULL string, prefix included, is the HMAC-SHA256 key for verifying the X-Factory-Signature header on deliveries. |
| `webhooks.createdAt` | string | When the subscription was created. Read-only. |
| `webhooks.updatedAt` | string | When the subscription was last changed. Read-only. |
| `nextPageToken` | string | Token to pass as `pageToken` to fetch the next page; empty when there are no more results. |

---

Source: https://developer.factory.app/reference/webhooks/list-webhooks · Factory Sales API v1
