> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gtm-api.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Search webhooks

> List webhook subscriptions owned by the caller's team with filter, sort and cursor pagination. Filter by status, subscribed event types (events.contains / contains_any), account narrowing or name; include=latest_webhook_logs for the recent-delivery view. secret is masked (null) on every read. Use this to find a webhook sid before calling webhook-scoped tools.

Contract:
- MCP tool `search_webhooks`, registry package `mcp.orchestration/webhooks`, mount `orchestration.webhooks`.
- Operation `search`, response envelope `search`.
- Flags: read only.



## OpenAPI

````yaml /api-reference/orchestration/openapi.yaml post /api/webhooks/search
openapi: 3.0.3
info:
  title: 'GTM API public contract: gtm.service.orchestration'
  description: >-
    The cross-service execution plane: the platform-wide webhook registry and
    delivery log, plus mass actions (preview, commit, pace, pause, resume,
    canary) and their per-item child rows.


    GENERATED. This document is projected from the Zod MCP tool registry in
    `product/mcp/gtm.mcp` (one tool per public endpoint, 1:1). Do not edit it by
    hand; edit the tool definition and regenerate with `pnpm openapi:public`.


    Surface: the public `/api` contract of `gtm.service.orchestration`, 21
    operations. Internal (`/internal`) and health endpoints are deliberately
    absent; the code-faithful spec that documents those lives in
    `product/openapi/gtm.openapi.tech`.


    Conventions:

    - Auth is a bearer JWT, optionally narrowed by the `Team-SID` header.

    - Every success body is an MCP envelope: `success: true` plus one typed
    `operation` shape (`search`, `get`, `create`, `update`, `delete`, `metrics`,
    `group_by`, `action`), and a `meta` block with `trace_id` for support.

    - Every failure is the same `McpError` envelope with a code from a fixed
    16-code taxonomy, so a client maps errors once.

    - Lists page with `page_size` (0 to 500, default 50) plus an opaque forward
    `cursor`; `page_size: 0` returns counts only.

    - On `GET` and `DELETE`, object-valued query parameters (`filter`, `sort`)
    travel as JSON text and array-valued ones repeat as `name[]=value`.

    - The MCP-only `_meta` field (usage analytics) never reaches the backend and
    is not part of this contract.
  version: '1.0'
  contact:
    name: GTM API
    url: https://gtm-api.com
    email: support@gtm-api.com
  license:
    name: Proprietary
    url: https://gtm-api.com/license
servers:
  - url: https://app.gtm-api.com/orchestration/v4
    description: Production, through the app.gtm-api.com gateway
  - url: http://localhost:8025
    description: Local Docker (gtm_orchestration_nginx_dev)
security:
  - BearerJwt: []
    TeamSid: []
tags:
  - name: mass_action_items
    description: >-
      Registry package `mcp.orchestration/mass_action_items`, served on MCP
      mount `orchestration.mass_actions`.
  - name: mass_actions
    description: >-
      Registry package `mcp.orchestration/mass_actions`, served on MCP mount
      `orchestration.mass_actions`.
  - name: webhook_logs
    description: >-
      Registry package `mcp.orchestration/webhook_logs`, served on MCP mount
      `orchestration.webhooks`.
  - name: webhooks
    description: >-
      Registry package `mcp.orchestration/webhooks`, served on MCP mount
      `orchestration.webhooks`.
paths:
  /api/webhooks/search:
    post:
      tags:
        - webhooks
      summary: Search webhooks
      description: >-
        List webhook subscriptions owned by the caller's team with filter, sort
        and cursor pagination. Filter by status, subscribed event types
        (events.contains / contains_any), account narrowing or name;
        include=latest_webhook_logs for the recent-delivery view. secret is
        masked (null) on every read. Use this to find a webhook sid before
        calling webhook-scoped tools.


        Contract:

        - MCP tool `search_webhooks`, registry package
        `mcp.orchestration/webhooks`, mount `orchestration.webhooks`.

        - Operation `search`, response envelope `search`.

        - Flags: read only.
      operationId: search_webhooks
      requestBody:
        required: false
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SearchWebhooksRequest'
      responses:
        '200':
          description: '`search` success envelope.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SearchWebhooksResponse'
        4XX:
          $ref: '#/components/responses/McpClientError'
        5XX:
          $ref: '#/components/responses/McpServerError'
components:
  schemas:
    SearchWebhooksRequest:
      type: object
      description: Request body of `search_webhooks`.
      properties:
        filter:
          type: object
          properties:
            status:
              type: object
              properties:
                eq:
                  type: string
                  enum:
                    - 'on'
                    - 'off'
                    - failed
                in:
                  type: array
                  items:
                    type: string
                    enum:
                      - 'on'
                      - 'off'
                      - failed
              additionalProperties: false
            events:
              type: object
              properties:
                eq:
                  type: string
                in:
                  type: array
                  items:
                    type: string
              additionalProperties: false
              description: >-
                eq: webhooks subscribed to this event type; in: subscribed to
                ANY of these (JSON-contains on the events array).
            name:
              type: object
              properties:
                eq:
                  type: string
            q:
              type: string
              description: Full-text over name / target_url.
            consecutive_failed_attempts:
              type: object
              properties:
                eq:
                  type: number
                gte:
                  type: number
                lte:
                  type: number
                gt:
                  type: number
                lt:
                  type: number
              additionalProperties: false
              description: >-
                Consecutive delivery failures (idx_wh_team_consecutive): the
                "close to failing" axis.
            last_failure_at:
              type: object
              properties:
                gte:
                  type: string
                lte:
                  type: string
                gt:
                  type: string
                lt:
                  type: string
              additionalProperties: false
              description: >-
                Timestamp of the most recent failed delivery
                (idx_wh_team_last_failure).
            created_at:
              type: object
              properties:
                gte:
                  type: string
                lte:
                  type: string
                gt:
                  type: string
                lt:
                  type: string
              additionalProperties: false
            updated_at:
              type: object
              properties:
                gte:
                  type: string
                lte:
                  type: string
                gt:
                  type: string
                lt:
                  type: string
              additionalProperties: false
            deleted_at:
              type: object
              properties:
                gte:
                  type: string
                lte:
                  type: string
              additionalProperties: false
            deleted:
              type: boolean
              description: true = include soft-deleted rows; default excludes them.
        include:
          type: array
          items:
            type: string
            enum:
              - latest_webhook_logs
          description: Relations to eager-load (see entity Includes).
        sort:
          type: object
          properties:
            field:
              type: string
              enum:
                - created_at
                - updated_at
                - name
            direction:
              type: string
              enum:
                - asc
                - desc
              description: Default desc.
          required:
            - field
        page_size:
          type: integer
          minimum: 0
          maximum: 500
          description: >-
            0..500, default 50. page_size=0 = count-only, page_size=1 =
            getFirst.
        cursor:
          type: string
          nullable: true
          description: >-
            Opaque forward cursor from a previous response
            pagination.next_cursor.
    SearchWebhooksResponse:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - true
        operation:
          type: string
          enum:
            - search
        items:
          type: array
          items:
            type: object
            properties:
              item:
                type: object
                properties:
                  sid:
                    type: string
                  team_sid:
                    type: string
                  name:
                    type: string
                  target_url:
                    type: string
                  events:
                    type: array
                    items:
                      type: string
                  filters:
                    type: object
                    additionalProperties: {}
                  secret:
                    type: string
                    nullable: true
                  status:
                    type: string
                    enum:
                      - 'on'
                      - 'off'
                      - failed
                  consecutive_failed_attempts:
                    type: number
                  last_failure_at:
                    type: string
                    nullable: true
                  created_by:
                    type: object
                    properties:
                      actor_type:
                        type: string
                        enum:
                          - user
                          - support
                          - api_key
                          - system
                      actor_sid:
                        type: string
                        nullable: true
                      team_sid:
                        type: string
                      permissions:
                        type: object
                        additionalProperties: {}
                      request_sid:
                        type: string
                        nullable: true
                      reason:
                        type: string
                        nullable: true
                    required:
                      - actor_type
                      - actor_sid
                      - team_sid
                      - permissions
                  deleted_by:
                    type: object
                    nullable: true
                    properties:
                      actor_type:
                        type: string
                        enum:
                          - user
                          - support
                          - api_key
                          - system
                      actor_sid:
                        type: string
                        nullable: true
                      team_sid:
                        type: string
                      permissions:
                        type: object
                        additionalProperties: {}
                      request_sid:
                        type: string
                        nullable: true
                      reason:
                        type: string
                        nullable: true
                    required:
                      - actor_type
                      - actor_sid
                      - team_sid
                      - permissions
                  created_at:
                    type: string
                  updated_at:
                    type: string
                  deleted_at:
                    type: string
                    nullable: true
                required:
                  - sid
                  - team_sid
                  - name
                  - target_url
                  - events
                  - filters
                  - status
                  - consecutive_failed_attempts
                  - last_failure_at
                  - created_by
                  - deleted_by
                  - created_at
                  - updated_at
                  - deleted_at
              included:
                type: object
                additionalProperties: {}
            required:
              - item
              - included
        pagination:
          type: object
          properties:
            next_cursor:
              type: string
              nullable: true
            has_more:
              type: boolean
            total_count:
              type: integer
              nullable: true
          required:
            - next_cursor
            - has_more
            - total_count
        applied_filters:
          type: object
          additionalProperties: {}
        includes:
          type: array
          items:
            type: string
        meta:
          type: object
          properties:
            trace_id:
              type: string
              description: UUID v7; same 128-bit value as the X-Trace-Id header.
            span_id:
              type: string
              pattern: ^[0-9a-f]{16}$
              description: 16 hex chars, root span of this request.
            timestamp:
              type: string
              description: ISO 8601 UTC (Y-m-dTH:i:sZ), response time.
            duration_ms:
              type: integer
              minimum: 0
              description: Server-side wall clock.
            debug_url:
              type: string
              description: Deep link to the post-call analysis UI.
          required:
            - trace_id
            - span_id
            - timestamp
            - duration_ms
            - debug_url
        counts:
          type: object
          properties: {}
      required:
        - success
        - operation
        - items
        - pagination
        - applied_filters
        - includes
        - meta
    McpError:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - false
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - validation_failed
                - nothing_to_update
                - not_found
                - relation_not_found
                - invalid_transition
                - limit_exceeded
                - payment_required
                - duplicate_rejected
                - conflict
                - delete_blocked
                - unauthorized
                - forbidden
                - rate_limited
                - internal_error
                - service_unavailable
                - not_implemented
            message:
              type: string
            recoverable:
              type: boolean
            suggestion:
              type: string
            field_errors:
              type: object
              additionalProperties:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: object
                      properties:
                        rule:
                          type: string
                        message:
                          type: string
                      required:
                        - rule
                        - message
            blockers:
              type: array
              items:
                type: object
                properties:
                  type:
                    type: string
                    description: >-
                      Machine-readable blocker type (active_flow, pending_tasks,
                      …).
                  severity:
                    type: string
                    enum:
                      - hard
                      - soft
                    description: >-
                      hard = external action required; soft = acknowledge is
                      enough.
                  description:
                    type: string
                  entity_sid:
                    type: string
                    nullable: true
                  count:
                    type: integer
                  resolution:
                    type: string
                    description: 'Hard: tool name to call. Soft: code for acknowledge[].'
                  resolution_hint:
                    type: string
                required:
                  - type
                  - severity
                  - description
                  - entity_sid
                  - resolution
                  - resolution_hint
            context:
              type: object
              additionalProperties: {}
          required:
            - code
            - message
            - recoverable
        meta:
          type: object
          properties:
            trace_id:
              type: string
              description: UUID v7; same 128-bit value as the X-Trace-Id header.
            span_id:
              type: string
              pattern: ^[0-9a-f]{16}$
              description: 16 hex chars, root span of this request.
            timestamp:
              type: string
              description: ISO 8601 UTC (Y-m-dTH:i:sZ), response time.
            duration_ms:
              type: integer
              minimum: 0
              description: Server-side wall clock.
            debug_url:
              type: string
              description: Deep link to the post-call analysis UI.
          required:
            - trace_id
            - span_id
            - timestamp
            - duration_ms
            - debug_url
      required:
        - success
        - error
  responses:
    McpClientError:
      description: >-
        MCP error envelope. `error.code` is one of validation_failed,
        nothing_to_update, not_found, relation_not_found, invalid_transition,
        limit_exceeded, payment_required, duplicate_rejected, conflict,
        delete_blocked, unauthorized, forbidden, rate_limited, not_implemented.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/McpError'
    McpServerError:
      description: >-
        MCP error envelope with `error.code` internal_error or
        service_unavailable.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/McpError'
  securitySchemes:
    BearerJwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Access token issued by gtm.service.id. Its `access_identity` claim
        carries `team_sid`, `actor_sid` and `actor_type`, and that team scope is
        authoritative.
    TeamSid:
      type: apiKey
      in: header
      name: Team-SID
      description: >-
        Team scope for tokens that do not carry one. Ignored when the token
        already names a team.

````