Reveal a subscription's full destination (admin only)
Returns one subscription’s FULL delivery destination, unmasked: the webhook URL with its path and query, the queue URL with its account id, the exchange/routing-key pair, the bus name, or the synthesized pull:// URL.
ADMIN ONLY. Every other read on this surface answers with ‘endpoint_display’, the show-safe rendering that keeps scheme and host and drops everything after them. This route is the one that does not, and the reason it is fenced is that a destination is a CAPABILITY, not a description of one: a webhook path routinely carries a per-subscription callback token, and anyone holding the full value can be delivered to. The operator and viewer roles are refused here by this gateway’s own authorization chain, before the request reaches the hub.
The body carries EXACTLY ONE key. No secret, no credential status, no other column of the row: this route answers a single question, and a body that grew the row’s other fields would put them behind the admin action as a side effect of nobody deciding to.
The 200 carries ‘Cache-Control: private, no-store’. The body is a live delivery capability rather than a view of one, so it must not reach a browser’s disk cache, a synced profile or a forward proxy, where it would outlive the session entitled to it.
This is a FORWARD, not a local read: the gateway owns no subscription storage. The hub answers an unknown subscription, a soft-deleted one and another tenant’s with the SAME 404, publishing no existence oracle, and that 404 reaches the caller unchanged. That uniformity matters more here than anywhere else on the surface: this route is reached with a strictly stronger grant, so a refusal that read differently would let an administrator of one tenant confirm that an id belongs to another.
The tenant is derived from the validated identity and is never read from the request.
Autorizaciones
JWT bearer token issued by the identity provider.
Encabezados
Bearer token, relayed to the streaming-hub as server-to-server auth.
"Bearer eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJvcHMifQ.signature"
Parámetros de ruta
Subscription id.
"0192f1a0-0000-7000-8000-0000000000ff"
Respuesta
OK
The full delivery destination as stored, unmasked: the webhook URL with its path and query, the queue URL with its account id, the exchange/routing-key pair, the bus name, or the synthesized pull:// URL.
"https://hooks.example.com/ingest"

