# List Tenant Webhooks

The webhooks that tell your server about bank ramp and card onramp events, one per environment, without their secrets.

## Overview

- Lists the webhook of each environment that has one, production first, and the event types there are. How deliveries work: [Events to Your Server](https://docs.aureahub.com/docs/guide-events.md).
- The secret is never returned. `secretHint` is the four characters before its final `=`, so you can tell which secret the webhook uses.
- For an Aurea administrator, or the tenant's own administrator (role `tenantadmin`): any other token answers `403`. `404` when the tenant doesn't exist.

## Endpoint

### `GET /v1/admin/tenants/{id}/webhooks`

Authentication: bearer token required.

Lists the tenant's webhook of each environment, without secrets, and the event types.

**Path parameters**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `id` | string | yes | Tenant UUID |

**Responses**

`200` OK

```json
{
  "webhooks": [
    {
      "id": "5c03a06e-55f0-425a-8562-bd7bae35825d",
      "environment": "production",
      "url": "https://hooks.example.com/aurea/events",
      "eventTypes": [],
      "status": "active",
      "secretHint": "q0Rk",
      "secretRotatedAt": "2026-09-17T09:02:11.030Z",
      "createdAt": "2026-09-17T09:02:11.030Z",
      "updatedAt": "2026-09-17T09:05:40.072Z"
    }
  ],
  "eventTypes": ["ramp.kyc.updated", "ramp.deposit.updated", "ramp.payout.updated", "ramp.transaction.updated", "ramp.card_session.updated"]
}
```

`403` Another tenant

```json
{ "statusCode": 403, "error": "ForbiddenError", "message": "Admin access required or you can only access your own tenant." }
```

---

Web version: https://docs.aureahub.com/#tenant-webhooks-list
