> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flowsign.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Flowsign is one word with a lowercase s.
> The REST API base URL is https://my.flowsign.app and every endpoint lives under /api/v1.
> When answering API questions, cite the HTTP method and endpoint path.
> API access needs the Enterprise plan and an API key with the API access permission.

# List webhook endpoints

> Returns the webhook subscriptions of the caller's workspace, newest first, a page at a time. Requires canManageWebhooks.



## OpenAPI

````yaml /api-reference/openapi.json get /api/v1/webhooks
openapi: 3.0.3
info:
  title: Flowsign API
  version: 1.0.0
  description: >-
    Public v1 API for Flowsign. Every endpoint is authenticated with a Bearer
    API key (prefix `fsk_`). Errors use `{ error, details? }`; success responses
    wrap payload data as `{ data }`.


    An organisation is divided into workspaces. A key is issued for one
    workspace and acts there on every request (see `GET /api/v1/workspaces`);
    `X-Workspace-Id` is optional and may only name that workspace. Packages,
    templates, contacts and members are scoped to the key's workspace.
servers:
  - url: https://my.flowsign.app
    description: Production
security:
  - ApiKey: []
paths:
  /api/v1/webhooks:
    get:
      tags:
        - Webhooks
      summary: List webhook endpoints
      description: >-
        Returns the webhook subscriptions of the caller's workspace, newest
        first, a page at a time. Requires canManageWebhooks.
      operationId: getWebhooks
      parameters:
        - schema:
            type: integer
            minimum: 1
            default: 1
            description: Page number, starting at 1.
            example: 1
          required: false
          name: page
          in: query
        - schema:
            type: integer
            minimum: 1
            maximum: 100
            default: 25
            description: Endpoints per page, 1 to 100.
            example: 25
          required: false
          name: pageSize
          in: query
        - schema:
            type: string
            description: >-
              The workspace the key was issued for, as returned by `GET
              /api/v1/workspaces`. Optional: omitting it acts in the key's
              workspace, and any other id is rejected with 401.
          required: false
          name: x-workspace-id
          in: header
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      webhooks:
                        type: array
                        items:
                          type: object
                          properties:
                            id:
                              type: string
                              description: Webhook endpoint id.
                              example: cmg1h7t2k0003v8p9d4q6xw2e
                            url:
                              type: string
                              description: HTTPS URL that receives event POSTs.
                              example: https://hooks.example.co.nz/flowsign
                            description:
                              type: string
                              nullable: true
                              description: >-
                                Free-text label set by the caller. Null when
                                none was given.
                              example: Production CRM sync
                            events:
                              type: array
                              items:
                                $ref: '#/components/schemas/WebhookEventType'
                              description: Events this endpoint is subscribed to.
                              example:
                                - PACKAGE_COMPLETED
                                - PACKAGE_DECLINED
                            enabled:
                              type: boolean
                              description: >-
                                Whether events are sent to this endpoint. A
                                disabled endpoint still records its events and
                                sends them, oldest first, once it is enabled
                                again.
                              example: true
                            status:
                              $ref: '#/components/schemas/WebhookEndpointStatus'
                            failureCount:
                              type: integer
                              minimum: 0
                              description: >-
                                Deliveries in a row that used up every retry
                                without a 2xx. Reset to 0 by a 2xx response or
                                by re-enabling the endpoint. At 10 the endpoint
                                is FAILING: its events are recorded but not sent
                                until it is re-enabled.
                              example: 0
                            secretRotatingUntil:
                              type: string
                              nullable: true
                              description: >-
                                While a rotated-out signing secret is still
                                honoured (ISO 8601): until then every delivery
                                carries a signature for both the new and the
                                previous secret. Null when no rotation is in
                                progress.
                              example: '2026-09-15T02:15:30.000Z'
                            lastDeliveryAt:
                              type: string
                              nullable: true
                              description: >-
                                When the most recent delivery attempt finished,
                                successful or not (ISO 8601). Null until the
                                first attempt.
                              example: '2026-09-14T02:15:30.000Z'
                            deliveryCount:
                              type: integer
                              minimum: 0
                              description: >-
                                Total deliveries recorded for this endpoint, in
                                any status.
                              example: 128
                            createdAt:
                              type: string
                              description: When the endpoint was registered (ISO 8601).
                              example: '2026-08-02T21:04:11.000Z'
                            updatedAt:
                              type: string
                              description: When the endpoint was last changed (ISO 8601).
                              example: '2026-09-10T00:42:07.000Z'
                          required:
                            - id
                            - url
                            - description
                            - events
                            - enabled
                            - status
                            - failureCount
                            - secretRotatingUntil
                            - lastDeliveryAt
                            - deliveryCount
                            - createdAt
                            - updatedAt
                        description: The requested page of endpoints, newest first.
                      totalCount:
                        type: integer
                        minimum: 0
                        description: >-
                          Total endpoints the caller's workspace can see across
                          all pages.
                        example: 3
                      page:
                        type: integer
                        minimum: 1
                        description: Page returned.
                        example: 1
                      pageSize:
                        type: integer
                        minimum: 1
                        description: Page size applied.
                        example: 25
                    required:
                      - webhooks
                      - totalCount
                      - page
                      - pageSize
                required:
                  - data
        '401':
          description: Missing or invalid API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '402':
          description: Caller's plan does not include this feature (publicApi / webhooks)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: API key present but caller lacks the required permission
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: Request failed schema validation; details keyed by field
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limit exceeded; see `Retry-After`
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    WebhookEventType:
      type: string
      enum:
        - PACKAGE_SENT
        - PACKAGE_COMPLETED
        - PACKAGE_VOIDED
        - PACKAGE_EXPIRED
        - PACKAGE_DECLINED
        - PACKAGE_ON_HOLD
        - PACKAGE_RESUMED
        - PACKAGE_SCHEDULED
        - PACKAGE_DELETED
        - SESSION_SENT
        - SESSION_OPENED
        - SESSION_COMPLETED
        - SESSION_DECLINED
        - SESSION_REMINDED
        - SESSION_CANCELLED
      description: >-
        Event name. PACKAGE_SENT: a package was sent to its recipients.
        PACKAGE_COMPLETED: every recipient finished and the package is complete.
        PACKAGE_VOIDED: the sender voided the package. PACKAGE_EXPIRED: the
        package passed its expiry before completing. PACKAGE_DECLINED: a
        recipient declined and the package stopped. PACKAGE_ON_HOLD: the sender
        paused signing on the package. PACKAGE_RESUMED: a package on hold went
        back out for signing. PACKAGE_SCHEDULED: the package was scheduled to
        send later, or moved to a new time. PACKAGE_DELETED: a package that was
        scheduled or out for signing was deleted. SESSION_SENT: one recipient's
        signing invitation was sent. SESSION_OPENED: a recipient opened their
        signing link. SESSION_COMPLETED: a recipient finished their step.
        SESSION_DECLINED: a recipient declined their step. SESSION_REMINDED: a
        recipient was sent a reminder. SESSION_CANCELLED: a recipient's open
        signing session ended because the package was declined, voided, expired
        or deleted, or a correction removed them.
      example: PACKAGE_COMPLETED
    WebhookEndpointStatus:
      type: string
      enum:
        - ACTIVE
        - PAUSED
        - FAILING
      description: >-
        ACTIVE delivers events. PAUSED is disabled by a member: events are still
        recorded and are delivered when the endpoint is enabled again. FAILING
        has had 10 deliveries in a row exhaust their retries: events are
        recorded but not sent until the endpoint is resumed, which replays them
        oldest first.
      example: ACTIVE
    Error:
      type: object
      properties:
        error:
          type: string
          description: What went wrong, in plain words.
          example: 'Missing permission: canSendPackages'
        details:
          type: object
          additionalProperties:
            type: array
            items:
              type: string
          description: >-
            Validation problems keyed by field path. Present only on 422
            responses.
          example:
            recipients.0.email:
              - Invalid email
      required:
        - error
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      bearerFormat: fsk_*

````