> ## Documentation Index
> Fetch the complete documentation index at: https://docs.encrata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get webhook

> Fetch one webhook, including its signing secret.

Returns a single webhook. This is the only endpoint that returns a `generic` webhook's signing secret after creation.

## Authentication

Send your API key as a bearer token.

```bash theme={"theme":{"light":"github-light","dark":"vesper"}}
Authorization: Bearer enc_xxxxxxxxxxxx
```

Any workspace role can read a webhook: `admin`, `tech`, or `readonly`. The `secret` field is returned only for `admin`.

## Request

<ParamField path="id" type="string" required>
  The webhook ID to fetch.
</ParamField>

<CodeGroup>
  ```bash cURL theme={"theme":{"light":"github-light","dark":"vesper"}}
  curl https://developer.encrata.com/api/webhooks/360cb300-d885-4c18-af2c-d259f936bb38 \
    -H "Authorization: Bearer enc_xxxxxxxxxxxx"
  ```

  ```python Python theme={"theme":{"light":"github-light","dark":"vesper"}}
  import requests

  webhook_id = "360cb300-d885-4c18-af2c-d259f936bb38"

  response = requests.get(
      f"https://developer.encrata.com/api/webhooks/{webhook_id}",
      headers={"Authorization": "Bearer enc_xxxxxxxxxxxx"},
  )

  webhook = response.json()["result"]
  print(webhook["url"], webhook.get("secret"))
  ```

  ```javascript Node.js theme={"theme":{"light":"github-light","dark":"vesper"}}
  const webhookId = "360cb300-d885-4c18-af2c-d259f936bb38";

  const response = await fetch(
    `https://developer.encrata.com/api/webhooks/${webhookId}`,
    { headers: { Authorization: "Bearer enc_xxxxxxxxxxxx" } },
  );

  const { result } = await response.json();
  console.log(result.url, result.secret);
  ```
</CodeGroup>

## Response

<ResponseField name="success" type="boolean">
  `true` when the request succeeded.
</ResponseField>

<ResponseField name="result" type="object">
  The webhook.

  <Expandable title="webhook" defaultOpen>
    <ResponseField name="id" type="string">
      Webhook identifier (UUID).
    </ResponseField>

    <ResponseField name="workspace_id" type="string">
      The workspace this webhook belongs to.
    </ResponseField>

    <ResponseField name="kind" type="string">
      Destination type: `generic`, `slack`, `discord`, or `telegram`.
    </ResponseField>

    <ResponseField name="url" type="string">
      The HTTPS URL that receives deliveries. Empty for `telegram`.
    </ResponseField>

    <ResponseField name="secret" type="string">
      The HMAC-SHA256 signing secret, used to verify `X-Encrata-Signature`.

      Returned only when both conditions hold: your role is `admin`, and `kind` is `generic`. A Telegram bot token is never returned.
    </ResponseField>

    <ResponseField name="events" type="string[]">
      The subscribed event types.
    </ResponseField>

    <ResponseField name="is_active" type="boolean">
      Whether Encrata currently delivers to this endpoint.
    </ResponseField>

    <ResponseField name="description" type="string">
      Your label for the webhook. Empty string when unset.
    </ResponseField>

    <ResponseField name="config" type="object">
      Destination-specific settings. Present only for `telegram`, carrying `chat_id`.
    </ResponseField>

    <ResponseField name="created_by" type="string | null">
      User ID of the creator, or `null` when unknown.
    </ResponseField>

    <ResponseField name="created_at" type="string">
      ISO 8601 creation timestamp.
    </ResponseField>

    <ResponseField name="updated_at" type="string">
      ISO 8601 last-updated timestamp.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="message" type="string">
  A human-readable summary.
</ResponseField>

```json Example response theme={"theme":{"light":"github-light","dark":"vesper"}}
{
  "success": true,
  "result": {
    "id": "360cb300-d885-4c18-af2c-d259f936bb38",
    "workspace_id": "51cdc9d9-203c-4345-b06d-222b560460aa",
    "kind": "generic",
    "url": "https://example.com/webhooks/encrata",
    "secret": "6cce5d5445b12e649ce9e715a2ef4addc9117d6bf3013a0f388997ed20711b1c",
    "events": ["lookup.completed", "credits.low"],
    "is_active": true,
    "description": "Production webhook",
    "created_by": "e861d7cb-1d7f-48d9-ab13-9af06a4055cf",
    "created_at": "2026-05-02T12:00:00Z",
    "updated_at": "2026-05-02T12:00:00Z"
  },
  "message": "Webhook loaded."
}
```

<Warning>
  Treat the `secret` like a password. Anyone holding it can forge a delivery that passes your signature check. If it leaks, delete the webhook and create a new one: secrets cannot be rotated in place.
</Warning>

## Errors

| Status | Code | When |
| - | - | - |
| `400` | `bad_request` | No ID was supplied in the path. |
| `401` | `unauthorized` | The API key is missing, revoked, or disabled. |
| `403` | `forbidden` | Your key resolves to no workspace membership. |
| `404` | `not_found` | No webhook with that ID exists in your workspace. |
| `500` | `internal` | Encrata could not load the webhook. Retry. |

```json Example error theme={"theme":{"light":"github-light","dark":"vesper"}}
{
  "success": false,
  "result": { "code": "not_found" },
  "message": "That webhook no longer exists. It may have been deleted."
}
```

## Next steps

<CardGroup cols={2}>
  <Card title="Verify signatures" icon="shield-check" href="/webhooks">
    Use the secret to validate every delivery.
  </Card>

  <Card title="List webhooks" icon="list" href="/api-reference/endpoint/webhook">
    See every endpoint in the workspace.
  </Card>

  <Card title="Send a test event" icon="paper-plane" href="/api-reference/endpoint/test-webhook">
    Confirm the endpoint is reachable.
  </Card>

  <Card title="Inspect deliveries" icon="list-check" href="/api-reference/endpoint/webhook-deliveries">
    Review attempts and retries.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.