Skip to main content
GET
List webhook endpoints
List tenant-owned Praxa webhook endpoint metadata without exposing any endpoint signing secret.
Availability: Partner preview. Required scope: runs:read.

Authenticate safely

Create a disposable personal workspace API key with exactly runs:read. Send it as Authorization: Bearer $PRAXA_API_KEY. A Gateway OAuth token, Supabase JWT, provider credential, or organization memory key is not interchangeable with this key. The hosted playground sends the credential from your browser session to the documented API through the configured playground proxy. Use test data, never share the key, and revoke it when the check ends.

Request fields

This operation has no path, query, header, or JSON-body fields beyond bearer authentication.

Runnable request examples

What success means

A 200 response returns only endpoint metadata for the authenticated tenant; signing secrets must be absent.

Successful response

200 — Tenant-owned webhook endpoint metadata.
v1
required
apiVersion response field.
array<object>
required
data response field.

Handle failures

Example problem

Verify the result

  1. Confirm every endpoint belongs to the intended environment.
  2. Require signing secrets to be absent.
  3. Test with an under-scoped key.

Retry, cleanup, and production use

  • Treat 401, 403, and 409 as authority or state signals, not generic retry prompts.
  • For 429 or retryable 5xx responses, follow server retry guidance and keep a bounded attempt budget.
  • Move the request into a trusted application backend before production; never ship the Praxa key in browser or mobile code.
  • Revoke the disposable key, disable test webhooks, and erase disposable candidate data after validation.
Continue with API authentication, the failure and retry guide, and the end-to-end coverage matrix.
Last modified on August 14, 2026