---
title: "List webhooks"
method: GET
path: "/webhooks"
tags: ["webhooks"]
---

# List webhooks

`GET /webhooks`

Gets the list of all *webhooks* that the user owns (if a user-generated
token was used to make the request) or the list of all webhooks associated
with the third-party app (if a third-party app made the request). Items in
the response are ordered by API creation date (most recent first).

**Note: In the response, each webhook's `events` field defaults to `["*.*"]`, regardless of its actual value.** Alternatively, call [GET /webhook/{webhookId}](/api/smartsheet/openapi/webhooks/getwebhook) on an individual webhook to get its `events` value.

## Query parameters

- `page` number
- `pageSize` number

## Response `200`

The List of Webhooks

- object
  - `pageNumber` number — The current page. **Note:** when a page number greater than total number of pages is requested, the last page is instead returned.
  - `pageSize` number, nullable — The number of items in the current page.
  - `totalPages` integer
  - `totalCount` integer
  - `data` Webhook[] — list of Webhooks
    - union — The webhook object.
      - object
        - `callbackUrl` string — HTTPS URL where callbacks are sent.
        - `name` string — Webhook name.
        - `id` number — ID of the webhook.
        - `apiClientId` string — ID of the corresponding third-party app that created the webhook. It's only present if the webhook was created by a third-party app.
        - `apiClientName` string — API client name corresponding to third-party app that created the webhook. It's only present if the webhook was created by a third-party app.
        - `createdAt` union
          - string, date-time
          - number
        - `disabledDetails` string — Details about the reason the webhook was disabled. It's only present when enabled=false.
        - `modifiedAt` union
          - string, date-time
          - number
        - `sharedSecret` string — Shared secret for this webhook, randomly generated by Smartsheet. See [Authenticating Callbacks](/api/smartsheet/guides/webhooks/webhook-callbacks#authenticating-callbacks-optional) for details about how this value can be used.
        - `stats` object
          - `lastCallbackAttempt` string, date-time — When this webhook last made a callback attempt.
          - `lastCallbackAttemptRetryCount` number — The number of retries the webhook had performed as of the last callback attempt.
          - `lastSuccessfulCallback` string, date-time — When this webhook last made a successful callback.
        - `events` string[] — Array of patterns for matching plan event types. Can contain either '\*.\*' (all events) and/or 'user.seatType.updated' (to monitor user seat type changes).
        - `scope` 'plan' — Scope of the subscription.
        - `scopeObjectId` integer — ID of the object whose events this webhook is subscribed to.
        - `status` 'DISABLED_ADMINISTRATIVE' | 'DISABLED_APP_REVOKED' | 'DISABLED_BY_OWNER' | 'DISABLED_CALLBACK_FAILED' | 'DISABLED_SCOPE_INACCESSIBLE' | 'DISABLED_VERIFICATION_FAILED' | 'ENABLED' | 'NEW_NOT_VERIFIED' — The webhook's status. See [Webhook Status](/api/smartsheet/guides/webhooks/webhook-status) for details.
        - `version` number — Webhook version. Currently, the only supported value is 1. This attribute is intended to ensure backward compatibility as new webhook functionality is released. For example, a webhook with a version of 1 is guaranteed to always be sent callback objects that are compatible with the version 1 release of webhooks.
        - `customHeaders` object — A set of custom headers that your webhook sends in all requests to your callback URL, where each key-value pair represents a header name and its corresponding value. This can be useful for passing authentication tokens or other information that your application needs to process the webhook events. **Important:** Don't use any of the following reserved headers as custom headers: - Accept-Encoding - Connection - Content-Length - Host - Proxy-Authenticate - Proxy-Authorization - Smartsheet-Change-Agent - Smartsheet-Hmac-SHA256 - Smartsheet-Hook-Challenge - Smartsheet-Hook-Response - TE - Trailer - Transfer-Encoding - Upgrade - User-Agent
        - `enabled` boolean — If `true`, the webhook is activated; Otherwise, it's inactive or deactivated.
      - object
        - `callbackUrl` string — HTTPS URL where callbacks are sent.
        - `name` string — Webhook name.
        - `id` number — ID of the webhook.
        - `apiClientId` string — ID of the corresponding third-party app that created the webhook. It's only present if the webhook was created by a third-party app.
        - `apiClientName` string — API client name corresponding to third-party app that created the webhook. It's only present if the webhook was created by a third-party app.
        - `createdAt` union
          - string, date-time
          - number
        - `disabledDetails` string — Details about the reason the webhook was disabled. It's only present when enabled=false.
        - `modifiedAt` union
          - string, date-time
          - number
        - `sharedSecret` string — Shared secret for this webhook, randomly generated by Smartsheet. See [Authenticating Callbacks](/api/smartsheet/guides/webhooks/webhook-callbacks#authenticating-callbacks-optional) for details about how this value can be used.
        - `stats` object
          - `lastCallbackAttempt` string, date-time — When this webhook last made a callback attempt.
          - `lastCallbackAttemptRetryCount` number — The number of retries the webhook had performed as of the last callback attempt.
          - `lastSuccessfulCallback` string, date-time — When this webhook last made a successful callback.
        - `events` string[] — Array of patterns for matching sheet event types. You can use `"*.*"` to subscribe to all event types (default), or specify one or more supported event patterns to receive only matching events: **Supported patterns:** | Pattern | Matches | |---|---| | `*.*` | All sheet event types | | `cell.*` | All cell events | | `cell.created` | Cell created | | `cell.updated` | Cell updated | | `cell.deleted` | Cell deleted | | `row.*` | All row events | | `row.created` | Row created | | `row.updated` | Row updated | | `row.deleted` | Row deleted | | `column.*` | All column events | | `column.created` | Column created | | `column.updated` | Column updated | | `column.deleted` | Column deleted | | `sheet.*` | All sheet events | | `sheet.created` | Sheet created | | `sheet.updated` | Sheet updated | | `sheet.deleted` | Sheet deleted | | `attachment.*` | All attachment events | | `attachment.created` | Attachment created | | `attachment.updated` | Attachment updated | | `attachment.deleted` | Attachment deleted | | `discussion.*` | All discussion events | | `discussion.created` | Discussion created | | `discussion.updated` | Discussion updated | | `discussion.deleted` | Discussion deleted | | `comment.*` | All comment events | | `comment.created` | Comment created | | `comment.updated` | Comment updated | | `comment.deleted` | Comment deleted | **Notes:** - You can combine multiple patterns, for example `["row.created", "cell.updated"]`. - Duplicate patterns are automatically deduplicated. - If `"*.*"` is included, it takes precedence over any other patterns. - Pattern matching is case-insensitive.
        - `scope` 'sheet' — Scope of the subscription.
        - `scopeObjectId` integer — ID of the object whose events this webhook is subscribed to.
        - `status` 'DISABLED_ADMINISTRATIVE' | 'DISABLED_APP_REVOKED' | 'DISABLED_BY_OWNER' | 'DISABLED_CALLBACK_FAILED' | 'DISABLED_EXCEEDED_GRID_LIMITS' | 'DISABLED_SCOPE_INACCESSIBLE' | 'DISABLED_VERIFICATION_FAILED' | 'ENABLED' | 'NEW_NOT_VERIFIED' — The webhook's status. See [Webhook Status](/api/smartsheet/guides/webhooks/webhook-status) for details.
        - `subscope` object — Limits the webhook to monitor specific columns designated by an array of sheet column IDs. **Note:** If a cell in one of the columns is deleted as part of a row deletion, the webhook still sends a `"row.deleted"` callback event.
          - `columnIds` integer[] — Array of IDs of the sheet columns to monitor.
        - `customHeaders` object — A set of custom headers that your webhook sends in all requests to your callback URL, where each key-value pair represents a header name and its corresponding value. This can be useful for passing authentication tokens or other information that your application needs to process the webhook events. **Important:** Don't use any of the following reserved headers as custom headers: - Accept-Encoding - Connection - Content-Length - Host - Proxy-Authenticate - Proxy-Authorization - Smartsheet-Change-Agent - Smartsheet-Hmac-SHA256 - Smartsheet-Hook-Challenge - Smartsheet-Hook-Response - TE - Trailer - Transfer-Encoding - Upgrade - User-Agent
        - `version` number — Webhook version. Currently, the only supported value is 1. This attribute is intended to ensure backward compatibility as new webhook functionality is released. For example, a webhook with a version of 1 is guaranteed to always be sent callback objects that are compatible with the version 1 release of webhooks.
        - `enabled` boolean — If `true`, the webhook is activated; Otherwise, it's inactive or deactivated.

## Other responses

- `default` — Generic Error Payload

---

[API](https://skmtc.net/smartsheet/apis/smartsheet-openapi-reference.md) · [All operations](https://skmtc.net/smartsheet/apis/smartsheet-openapi-reference/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/smartsheet/smartsheet-openapi-reference/versions/b4afda95fb51/schema)
