# Retrieve a webhook endpoint's public key

`GET https://api.morevoice.ai/v1/webhook_endpoints/{id}/public_key`

The Ed25519 public key that verifies an `ed25519` endpoint's `v1a` signatures, as `whpk_…` (Standard Webhooks) and as SPKI PEM, with the previous key while a rotation overlaps. An `hmac` endpoint has none (409 `resource_conflict`).

Authenticate with a secret API key: `Authorization: Bearer $MOREVOICE_API_KEY`.

Operation ID: `webhook_endpoints_retrieve_public_key`.

## Parameters

### Path parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `id` | `string` | yes | A webhook endpoint ID (`we_…`). |

### Headers

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `MoreVoice-Version` | `string` | no | The API version to use for this request. Defaults to the version the API key is pinned to. |

## Responses

### 200 OK

OK Returns `WebhookEndpointPublicKey`.

| Field | Type | Description |
| --- | --- | --- |
| `object` | `"webhook_endpoint_public_key"` | — |
| `endpoint_id` | `string` | A webhook endpoint ID (prefix `we_`). |
| `algorithm` | `"ed25519"` | — |
| `signature_version` | `"v1a"` | The `webhook-signature` entries these keys verify (`v1a,<base64 signature>`). |
| `public_key` | `string \| null` | The current key: `whpk_` + base64 of the 32-byte Ed25519 public key (Standard Webhooks format). Null while an endpoint switched back to `hmac` still overlaps with its last Ed25519 key. |
| `public_key_pem` | `string \| null` | The same key as SPKI PEM, for libraries that load PEM. |
| `previous_public_key` | `string \| null` | After a rotation: the previous key, which still signs alongside the current one until `previous_expires_at`. |
| `previous_public_key_pem` | `string \| null` | — |
| `previous_expires_at` | `string \| null` | — |
| `livemode` | `boolean` | `true` in live mode, `false` in test mode. |

Example:

```json
{
  "algorithm": "ed25519",
  "endpoint_id": "we_5Hl3MnO0qR5sT7uW9xY1zA",
  "livemode": true,
  "object": "webhook_endpoint_public_key",
  "previous_expires_at": null,
  "previous_public_key": null,
  "previous_public_key_pem": null,
  "public_key": "whpk_7GfYlAqTA3D8UzyF8UoSc4n3+HcTsNFWO4gUnF2xOd0=",
  "public_key_pem": "-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEA7GfYlAqTA3D8UzyF8UoSc4n3+HcTsNFWO4gUnF2xOd0=\n-----END PUBLIC KEY-----\n",
  "signature_version": "v1a"
}
```

### 400 Bad Request

The request is invalid: a parameter is missing, malformed or unknown, or the version header is unknown. Returns `ErrorEnvelope`.

### 401 Unauthorized

No valid API key was sent. Returns `ErrorEnvelope`.

### 403 Forbidden

The key may not do this (a missing scope, a plan limit, or a compliance block). Returns `ErrorEnvelope`.

### 404 Not Found

No object with this ID exists in this organisation and mode. Returns `ErrorEnvelope`.

### 429 Too Many Requests

Too many requests, or no call capacity right now. Retry after the Retry-After delay. Returns `ErrorEnvelope`.

### 500 Internal Server Error

Something went wrong on MoreVoice's side. Retry with the same Idempotency-Key. Returns `ErrorEnvelope`.

## Code samples

**TypeScript**

```ts
import MoreVoice from "@morevoice/sdk";

const mv = new MoreVoice(); // MOREVOICE_API_KEY from the environment

const webhookEndpointPublicKey = await mv.webhookEndpoints.retrievePublicKey("we_7Hk2Lm9Qp");
console.log(webhookEndpointPublicKey);
```

**Python**

```python
from morevoice import MoreVoice

client = MoreVoice()  # MOREVOICE_API_KEY from the environment

webhook_endpoint_public_key = client.webhook_endpoints.retrieve_public_key("we_7Hk2Lm9Qp")
print(webhook_endpoint_public_key)
```

**cURL**

```sh
curl https://api.morevoice.ai/v1/webhook_endpoints/we_7Hk2Lm9Qp/public_key \
  -H "Authorization: Bearer $MOREVOICE_API_KEY"
```
