---
title: "List Application Webapp Allowed Origins"
method: GET
path: "/v2/applications/{application_id}/webapp_origins"
tags: ["Application Webapp Origins V2"]
---

# List Application Webapp Allowed Origins

`GET /v2/applications/{application_id}/webapp_origins`

Returns the allowed origins for an application. Requires applications:read scope.

## Path parameters

- `application_id` string, required — Application ID

## Query parameters

- `limit` string — a string to be decoded into a number
- `starting_after` string — a string to be decoded into a number
- `ending_before` string — a string to be decoded into a number

## Response `200`

Success

- object
  - `object` 'list', required — Object type, always `list`
  - `url` '/v2/applications/webapp_origins', required — API endpoint URL for this list
  - `has_more` boolean, required — Whether there are more results available beyond this page
  - `data` object[], required — List of results
    - `id` string, required — Unique identifier for the allowed origin
    - `object` 'application_webapp_origin', required — Object type, always `application_webapp_origin`
    - `application_id` string, required — ID of the application this origin belongs to
    - `origin` string, required — Allowed browser origin (scheme + host only, e.g. `https://merchant.com`)
    - `created_at` string, required — ISO 8601 timestamp of when the origin was added

## Other responses

- `400` — The request did not match the expected schema
- `401` — No API key was provided in the request
- `403` — The API key does not have permission to perform this action
- `404` — The requested resource was not found
- `429` — Too many requests have been made in a short period
- `500` — An unexpected error occurred on the server

---

[API](https://skmtc.dev/superwall/apis/superwall-api-v2.md) · [All operations](https://skmtc.dev/superwall/apis/superwall-api-v2/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/superwall/superwall-api-v2/revisions/e04f76c478af/schema)
