# List webhook endpoints
Source: https://www.desktopaccountingapi.com/docs/api/reference/operations/webhookendpointslist/

`GET https://api.desktopaccountingapi.com/v1/webhook-endpoints`

Operation ID: `webhookEndpoints.list`. Tag: Webhooks.

Returns the project's webhook endpoints, newest first.

Authentication: `Authorization: Bearer <secret key>`.

## Query parameters

- `cursor` (string): The `nextCursor` from the previous page. 1–200 characters.
- `limit` (integer): Page size, 1–100. Default 50. 1 to 100; default `50`; example `50`.

## Responses

### 200

A page of endpoints.

Body (application/json): object (WebhookEndpointList).

- `objectType` (string, required): Always `list`. one of `list`.
- `url` (string, required): The endpoint that produced this list. one of `/v1/webhook-endpoints`.
- `data` (array of object (WebhookEndpoint), required): Objects on this page, newest first.
  - `id` (string, required): Unique identifier for the webhook endpoint. example `whe_01j9x4m6v4c8k2t7q0r5s3w1zg`.
  - `objectType` (string, required): Always `webhook_endpoint`. one of `webhook_endpoint`.
  - `createdAt` (string (date-time), required): When the endpoint was created. UTC, ISO 8601 with milliseconds. example `2026-10-05T16:03:59.002Z`.
  - `projectId` (string, required): Unique identifier for the project. example `proj_01j9x4m6v4c8k2t7q0r5s3w1zf`.
  - `url` (string, required): Where events are delivered.
  - `description` (string, nullable, required): Your note about the endpoint.
  - `eventTypes` (array of string, required): Subscribed event types.
  - `enabled` (boolean, required): Whether events are delivered.
  - `disabledReason` (string, nullable, required): Why the endpoint was disabled automatically (5 days of failed deliveries), or `null`.
  - `includeSyncRequests` (boolean, required): Whether request events of synchronous calls whose caller received the result are delivered.
  - `secretRotatedAt` (string, nullable, required): When the signing secret was last rotated. UTC, ISO 8601.
  - `previousSecretExpiresAt` (string, nullable, required): Until when deliveries also carry a signature made with the previous secret. UTC, ISO 8601.
- `nextCursor` (string, nullable, required): Pass as `cursor` to fetch the next page; `null` on the last page.
- `hasMore` (boolean, required): Whether another page exists.
- `remainingCount` (integer, nullable, required): Always `null` for platform lists.
- `cursorExpiresAt` (string, nullable, required): Always `null`: platform cursors do not expire.

### Errors

Every error body is the error object described at https://www.desktopaccountingapi.com/docs/errors/.

- `400`: The request is invalid. Codes: `UNKNOWN_HEADER`, `INVALID_PARAMETER`, `CURSOR_INVALID`.
- `401`: The API key is missing or invalid. Codes: `API_KEY_MISSING`, `API_KEY_INVALID`.
- `429`: Too many requests. Codes: `RATE_LIMITED`.
- `500`: Unexpected server error. Codes: `INTERNAL_ERROR`.
- `503`: QuickBooks Desktop or the service is not available. Codes: `SERVICE_UNAVAILABLE`.
