Skip to content

Retrieve a webhook endpoint's public key

GET
/webhook_endpoints/{id}/public_key
import MoreVoice from "@morevoice/sdk";
const mv = new MoreVoice(); // MOREVOICE_API_KEY from the environment
const webhookEndpointPublicKey = await mv.webhookEndpoints.retrievePublicKey("we_7Hk2Lm9Qp");
console.log(webhookEndpointPublicKey);

The Ed25519 public key that verifies an ed25519 endpoint’s v1a signatures, as whpk_… (Standard Webhooks) and as SPKI PEM, with the previous key while a rotation overlaps. An hmac endpoint has none (409 resource_conflict).

Try it in the API playground with a test-mode key.

id
required
string
<= 200 characters /^we_[0-9A-Za-z]+$/

A webhook endpoint ID (we_…).

MoreVoice-Version
string
/^\d{4}-\d{2}-\d{2}$/

The API version to use for this request. Defaults to the version the API key is pinned to.

Example
2026-11-01

OK

Media typeapplication/json

The Ed25519 public key(s) that verify an ed25519 endpoint’s v1a signatures (Standard Webhooks asymmetric scheme).

object
algorithm
required
string
Allowed value: ed25519
endpoint_id
required

A webhook endpoint ID (prefix we_).

string
/^we_[0-9A-Za-z]+$/
livemode
required

true in live mode, false in test mode.

boolean
object
required
string
Allowed value: webhook_endpoint_public_key
previous_expires_at
required
Any of:

An ISO-8601 timestamp in UTC.

string format: date-time
previous_public_key
required

After a rotation: the previous key, which still signs alongside the current one until previous_expires_at.

string | null
previous_public_key_pem
required
string | null
public_key
required

The current key: whpk_ + base64 of the 32-byte Ed25519 public key (Standard Webhooks format). Null while an endpoint switched back to hmac still overlaps with its last Ed25519 key.

string | null
public_key_pem
required

The same key as SPKI PEM, for libraries that load PEM.

string | null
signature_version
required

The webhook-signature entries these keys verify (v1a,<base64 signature>).

string
Allowed value: v1a
Example
{
"algorithm": "ed25519",
"endpoint_id": "we_5Hl3MnO0qR5sT7uW9xY1zA",
"livemode": true,
"object": "webhook_endpoint_public_key",
"previous_expires_at": null,
"previous_public_key": null,
"previous_public_key_pem": null,
"public_key": "whpk_7GfYlAqTA3D8UzyF8UoSc4n3+HcTsNFWO4gUnF2xOd0=",
"public_key_pem": "-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEA7GfYlAqTA3D8UzyF8UoSc4n3+HcTsNFWO4gUnF2xOd0=\n-----END PUBLIC KEY-----\n",
"signature_version": "v1a"
}

The request is invalid: a parameter is missing, malformed or unknown, or the version header is unknown.

Media typeapplication/json

Every /v1 error.

object
error
required
object
code
required

A stable, machine-readable code from the error-code catalogue.

string
details

Structured context, e.g. required_scope or the compliance verdict.

object
key
additional properties
doc_url
required

A link to the documentation of this code.

string
message
required

A human-readable explanation. Do not parse it.

string
param

The request parameter the error relates to, e.g. to or metadata[order_id].

string
request_id
required

The X-Request-Id of this request. Quote it when you contact support.

string
type
required

The category of the error.

string
Allowed values: invalid_request_error authentication_error permission_error not_found conflict rate_limit_error compliance_error idempotency_error api_error
Example
{
"error": {
"code": "parameter_missing",
"doc_url": "https://docs.morevoice.ai/api/errors#parameter-missing",
"message": "Missing required parameter: to.",
"param": "to",
"request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ",
"type": "invalid_request_error"
}
}
X-Request-Id
string

The request’s ID (req_…). Quote it when you contact support.

No valid API key was sent.

Media typeapplication/json

Every /v1 error.

object
error
required
object
code
required

A stable, machine-readable code from the error-code catalogue.

string
details

Structured context, e.g. required_scope or the compliance verdict.

object
key
additional properties
doc_url
required

A link to the documentation of this code.

string
message
required

A human-readable explanation. Do not parse it.

string
param

The request parameter the error relates to, e.g. to or metadata[order_id].

string
request_id
required

The X-Request-Id of this request. Quote it when you contact support.

string
type
required

The category of the error.

string
Allowed values: invalid_request_error authentication_error permission_error not_found conflict rate_limit_error compliance_error idempotency_error api_error
Example
{
"error": {
"code": "invalid_api_key",
"doc_url": "https://docs.morevoice.ai/api/errors#invalid-api-key",
"message": "Invalid API key.",
"request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ",
"type": "authentication_error"
}
}
X-Request-Id
string

The request’s ID (req_…). Quote it when you contact support.

The key may not do this (a missing scope, a plan limit, or a compliance block).

Media typeapplication/json

Every /v1 error.

object
error
required
object
code
required

A stable, machine-readable code from the error-code catalogue.

string
details

Structured context, e.g. required_scope or the compliance verdict.

object
key
additional properties
doc_url
required

A link to the documentation of this code.

string
message
required

A human-readable explanation. Do not parse it.

string
param

The request parameter the error relates to, e.g. to or metadata[order_id].

string
request_id
required

The X-Request-Id of this request. Quote it when you contact support.

string
type
required

The category of the error.

string
Allowed values: invalid_request_error authentication_error permission_error not_found conflict rate_limit_error compliance_error idempotency_error api_error
Example
{
"error": {
"code": "missing_scope",
"doc_url": "https://docs.morevoice.ai/api/errors#missing-scope",
"message": "This API key lacks the calls:write scope.",
"request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ",
"type": "permission_error"
}
}
X-Request-Id
string

The request’s ID (req_…). Quote it when you contact support.

No object with this ID exists in this organisation and mode.

Media typeapplication/json

Every /v1 error.

object
error
required
object
code
required

A stable, machine-readable code from the error-code catalogue.

string
details

Structured context, e.g. required_scope or the compliance verdict.

object
key
additional properties
doc_url
required

A link to the documentation of this code.

string
message
required

A human-readable explanation. Do not parse it.

string
param

The request parameter the error relates to, e.g. to or metadata[order_id].

string
request_id
required

The X-Request-Id of this request. Quote it when you contact support.

string
type
required

The category of the error.

string
Allowed values: invalid_request_error authentication_error permission_error not_found conflict rate_limit_error compliance_error idempotency_error api_error
Example
{
"error": {
"code": "resource_missing",
"doc_url": "https://docs.morevoice.ai/api/errors#resource-missing",
"message": "No such object: 'call_4Gk2'.",
"param": "id",
"request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ",
"type": "not_found"
}
}
X-Request-Id
string

The request’s ID (req_…). Quote it when you contact support.

Too many requests, or no call capacity right now. Retry after the Retry-After delay.

Media typeapplication/json

Every /v1 error.

object
error
required
object
code
required

A stable, machine-readable code from the error-code catalogue.

string
details

Structured context, e.g. required_scope or the compliance verdict.

object
key
additional properties
doc_url
required

A link to the documentation of this code.

string
message
required

A human-readable explanation. Do not parse it.

string
param

The request parameter the error relates to, e.g. to or metadata[order_id].

string
request_id
required

The X-Request-Id of this request. Quote it when you contact support.

string
type
required

The category of the error.

string
Allowed values: invalid_request_error authentication_error permission_error not_found conflict rate_limit_error compliance_error idempotency_error api_error
Example
{
"error": {
"code": "rate_limited",
"doc_url": "https://docs.morevoice.ai/api/errors#rate-limited",
"message": "Too many requests. Retry after 1 second.",
"request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ",
"type": "rate_limit_error"
}
}
Retry-After
integer

Seconds to wait before retrying.

X-Request-Id
string

The request’s ID (req_…). Quote it when you contact support.

Something went wrong on MoreVoice’s side. Retry with the same Idempotency-Key.

Media typeapplication/json

Every /v1 error.

object
error
required
object
code
required

A stable, machine-readable code from the error-code catalogue.

string
details

Structured context, e.g. required_scope or the compliance verdict.

object
key
additional properties
doc_url
required

A link to the documentation of this code.

string
message
required

A human-readable explanation. Do not parse it.

string
param

The request parameter the error relates to, e.g. to or metadata[order_id].

string
request_id
required

The X-Request-Id of this request. Quote it when you contact support.

string
type
required

The category of the error.

string
Allowed values: invalid_request_error authentication_error permission_error not_found conflict rate_limit_error compliance_error idempotency_error api_error
Example
{
"error": {
"code": "internal_error",
"doc_url": "https://docs.morevoice.ai/api/errors#internal-error",
"message": "Something went wrong on MoreVoice's side.",
"request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ",
"type": "api_error"
}
}
X-Request-Id
string

The request’s ID (req_…). Quote it when you contact support.