List Webhook Events
GET/api/shiprush/instances/:integration_instance/webhooks
Paginated, filterable list of inbound store-endpoint events received from ShipRush for the instance, newest first. Every inbound writeback (shipnotify / credential_failed / duplicate) and every rejected export poll (export_rejected — e.g. a start_date or end_date ShipRush sent in an unparseable format; the poll gets HTTP 400) is persisted so you can audit and re-run deliveries; each row records the event type, dedup key, order/tracking numbers, the raw payload, whether the credentials were valid, and whether it has been processed (processed / processed_at) plus any error.
This endpoint currently requires session authentication; Personal Access Token scope support is in progress.
Every filter[<column>] parameter also accepts an operator suffix as filter[<column>.<operator>]=<value>; a bare filter[<column>]=<value> is treated as "is". filter[search] does a fuzzy partial match across order_number, tracking_number, and event_type.
Sort field. Prefix with - for descending. Allowed: id, event_type, order_number, tracking_number, credential_valid, processed, received_at, processed_at, created_at, updated_at. Default: -id (newest first).
Results are paginated; per_page defaults to 10.
Authentication: Requires a Bearer token.
Request
Responses
- 200
- 401
- 403
- 404
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.