List webhook endpoints
/webhook-endpointsReturns the webhook endpoints for the mode of your key, newest first. Live and test mode have separate endpoints. Secrets are never included; they are shown once, when you create or rotate them.
Scope: webhooks:manage · Plan: Growth, Pro and Enterprise in live mode; every plan in test mode.
Send Authorization: Bearer <token> on every request. The token is one of:
| Prefix | What it is | Where it may be used |
|---|---|---|
agoo_sk_live_ | Secret key, live mode | Your servers only |
agoo_sk_test_ | Secret key, test mode | Your servers only |
agoo_pk_live_ | Publishable key, live mode | Browsers and apps: create pre-registrations and bookings, read public booking types (with their intake questions) and their free slots, read the visit types open for pre-registration with their public forms. Never lists people. |
agoo_pk_test_ | Publishable key, test mode | As above, in test mode |
Admins create keys in Console → Developers → API keys and choose each key's scopes. A key is shown once. Never put a secret key in a URL, a browser or a mobile app.
In: header
Scope: webhooks:manage
Query Parameters
How many items to return, from 1 to 100.
1 <= value <= 10025The next_cursor from the previous page. Leave it out for the first page.
length <= 512Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/webhook-endpoints?limit=25"{ "data": [ { "id": "whep_01m2jf0cg0ffyrmjbzsk9t0gtc", "url": "https://hooks.voltabank.example/agoo", "description": "Front desk integration", "enabled_events": [ "visit.checked_in", "visit.checked_out", "delivery.received" ], "status": "enabled", "disabled_reason": null, "created_at": "2026-09-15T12:00:00Z", "updated_at": "2026-09-15T12:00:00Z" } ], "next_cursor": null, "has_more": false}Close a roll call POST
Closes an `active` roll call and fires `roll_call.closed`. The final counts and list are kept for your records. A roll call that is already closed returns `invalid_state`. **Scope:** `rollcalls:write` · **Plan:** Pro and Enterprise in live mode; every plan in test mode.
Create a webhook endpoint POST
Registers a URL to receive events. The response includes the endpoint's signing `secret`, **shown only this once**. Store it with your other secrets and use it to verify every delivery. - `url` must be a public HTTPS address, without a user name or password. Its host must resolve, and only to public addresses: Agoo checks when you save it and again before every delivery. Agoo doesn't follow redirects. - List the event types you want in `enabled_events`, or `["*"]` for every type, including types added later, except `watchlist.matched`, which an endpoint receives only by listing it. - An endpoint created with a test key receives test-mode events (`livemode: false`) only. **Scope:** `webhooks:manage` · **Plan:** Growth, Pro and Enterprise in live mode; every plan in test mode.