Skip to main content
GET
Get a webhook endpoint

Authorizations

Authorization
string
header
required

An API key of one app, sent as Authorization: Bearer <key>. Keys start with fk_test_ (test mode: sandbox senders and test data only) or fk_live_ (live mode). Keep live keys on your server; never ship them in an app or page.

Headers

Flow-Version
string<date>

The API version to use, as a date. Without it, the version pinned to your app when it was created is used.

Example:

"2026-11-01"

Path Parameters

webhook_endpoint_id
string
required

The webhook endpoint's ID. A webhook endpoint ID, we_ and a ULID.

Pattern: ^we_[0-9A-HJKMNP-TV-Z]{26}$
Example:

"we_01JB8ZF6P8R0T2W4Y6A8C0E2F4"

Response

The webhook endpoint.

A URL that receives your app's events of the types it subscribes to.

id
string
required

A webhook endpoint ID, we_ and a ULID.

Pattern: ^we_[0-9A-HJKMNP-TV-Z]{26}$
Example:

"we_01JB8ZF6P8R0T2W4Y6A8C0E2F4"

url
string<uri>
required

The HTTPS URL events are posted to.

events
enum<string>[]
required

The event types delivered to this endpoint.

  • message.received: the contact sent something with content (a button tap arrives as button_reply content).
  • message.sent, message.delivered, message.read, message.failed: the status of your outbound messages. message.failed carries the error in data.message.error.
  • reaction.added, reaction.removed: the contact reacted to a message.
  • typing.started, typing.stopped: the contact is typing, where the channel reports it.
  • conversation.started: the first inbound message from a new contact, or a sandbox join (Flow itself answers the join; the join message is not a message.received).
  • conversation.window_closing: WhatsApp only, opt-in. The 24-hour window closes in 1 hour.
  • sender.status_changed: a sender was throttled, flagged, banned or restored, or its WhatsApp quality rating changed.
  • template.status_changed: Meta approved, rejected or paused a template.
Available options:
message.received,
message.sent,
message.delivered,
message.read,
message.failed,
reaction.added,
reaction.removed,
typing.started,
typing.stopped,
conversation.started,
conversation.window_closing,
sender.status_changed,
template.status_changed
enabled
boolean
required

Whether events are delivered. Disabled endpoints keep their place; nothing is lost from the log.

livemode
boolean
required

Whether the endpoint receives live-mode or test-mode events.

created_at
string<date-time>
required

When the endpoint was created.

description
string

Your note about the endpoint.

secret
string

The signing secret (whsec_...). Only in the answers to create and to rotate the secret.

previous_secret_expires_at
string<date-time>

While a secret rotation overlaps, when the previous secret stops signing. Absent when only one secret is active.