Webhook dispatcher observability snapshot (password-protected)
Operator-facing, not tenant-facing: aggregate, cross-tenant webhook delivery health (pending count, oldest pending age, outcome counters, latency, worker utilization, per-destination-host failure rate) for this process's dispatcher. Gated by the same Basic Auth as /docs, never the per-tenant v1 auth group, since this is cross-tenant volume/health data no single authenticated caller's own webhooks should reveal.
View as MarkdownAuthorization
docsBasic Gates /docs, /docs/openapi.yaml, and /debug/webhooks/stats. Credentials come from the DOCS_USER/DOCS_PASSWORD env vars; if either is unset the routes are not registered at all (404), never served open.
In: header
Response Body
application/json
curl -X GET "https://example.com/debug/webhooks/stats"{ "succeeded": 0, "failed": 0, "retried": 0, "dead": 0, "deferred": 0, "avgDeliveryLatencyMs": 0, "avgClaimLatencyMs": 0, "workerUtilization": 0, "pendingCount": 0, "oldestPendingAgeSeconds": 0, "destinationFailureRates": { "property1": 0, "property2": 0 }}This contract, served by the running instance (password-protected)
The embedded copy of this OpenAPI document — backs the reference UI above and is handy for local codegen against a running instance. Same Basic Auth gate as /docs.
List the links the caller can read
Links the caller can read, newest first, paginated: their own (active-org-scoped; legacy rows without org_id stay visible) plus any shared with the organization by a teammate. Archived links are hidden unless archived=1. q searches title/destination/code server-side; status and tag filter; sort=clicks orders by click count.