List this tenant's webhook subscriptions
Returns every subscription of the authenticated tenant with its destination, subscribed events, status and current secret version. No signing secret is ever included.
Returns every subscription of the authenticated tenant with its destination, subscribed events, status and current secret version. No signing secret is ever included.
Authorization
bearerAuth Tenant-bound, scoped and expiring Apifact credential. Migrated legacy credentials are accepted only on deprecated v1 writes and tenant-scoped v2 read, poll and download routes. Each operation names the single scope it requires in x-required-scope; the scope array of the security requirement itself is empty because OpenAPI 3.0 requires it to be for a non-oauth2 scheme.
In: header
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/api/v2/webhooks/subscriptions" \ -H "Authorization: Bearer apf_v2_tu_credencial"{ "schemaVersion": "2.0", "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6", "subscriptions": [ { "subscriptionId": "d079718b-ff63-45dd-947b-4950c023750f", "url": "http://example.com", "events": [ "document.accepted" ], "status": "ACTIVE", "description": "string", "secretVersion": 1, "createdAt": "2019-08-24T14:15:22Z", "updatedAt": "2019-08-24T14:15:22Z" } ]}Durably request comprobante de percepción (CPE, 40) dispatch POST POST
The perception mirror of submitRetention: same 'otros CPE' service, same single-envelope fence, same AMBIGUOUS outcome for a dispatch whose CDR never arrived. Gated by submission_publication_enabled AND perception_issuance_enabled.
Register a signed webhook destination for this tenant POST POST
Registers an HTTPS destination and the versioned events it should receive, and mints the HMAC signing secret. The secret is returned EXACTLY ONCE, in this response: the API's database role holds no read privilege on the column that stores it, so it cannot be retrieved later by any route. A replay of the same Idempotency-Key answers 200 with replay=true and no secret. Destinations are admitted by an anti-SSRF gate: https only, default port only, no credentials in the URL, no fragment, and the host must be a public DNS name whose last label is alphabetic, which refuses every IP literal in every base as well as localhost, .internal, .local and cloud metadata names.