Skip to main content
GET
cURL
Use this endpoint to diagnose a missing webhook event. Each row shows whether a delivery was attempted, your receiver’s latest response, and the next retry time. To retry a delivery marked dead_letter, use Redeliver a webhook delivery.

Parameters

Key response fields

Why a retry is scheduled when it is

Retry schedule

Each delivery gets 8 attempts. The wait after each failure is capped at the value below, and the 8th failure sets status to dead_letter.
  • A transient_failure waits somewhere between half the cap and the cap. The wait is derived from the delivery’s own id, so it never moves once next_attempt_at is set.
  • A permanent_or_auth_failure waits exactly the cap.
  • A receiver_retry_after uses your Retry-After value in place of that one wait, clamped to between 60 and 3,600 seconds. A missing, malformed, or past value is ignored and the ordinary wait applies.
  • The queue is polled every 10 seconds, so an attempt can be up to 10 seconds later than next_attempt_at.
Those caps add up to the retry_policy.retry_horizon_seconds value of 7380. Separately, 8 consecutive failed attempts across all of an endpoint’s deliveries disable the endpoint and dead-letter everything still queued for it. Any successful attempt resets that count.

Example

What it does not return

  • The request body or the signing secret. A delivery row never repeats either one.
  • A delivered or dead_letter row more than 7 days after it last changed. Retention deletes it.
  • A log for an endpoint you do not own, or one you deleted. Both answer 404, the same answer as an id that never existed.
  • A status or event_type filter. Page through the log and filter on your side.
  • The delivery’s own idempotency-key header value. Deduplicate on event_id instead.

Authorizations

Authorization
string
header
required

Legacy default or named integration API key, or OAuth 2.1 access token, in the Authorization header as Bearer oxi_sk_live_... or Bearer oxi_at_.... Default keys retain full access; integration keys are limited to their approved read, webhooks, export and usage scopes and expire within 90 days. All credentials share the owner's account limits. Data calls require an active Pro subscription and return live data. A 401 carries WWW-Authenticate: Bearer resource_metadata="https://api.0xinsider.com/.well-known/oauth-protected-resource" (RFC 6750 section 3, RFC 9728).

Headers

X-Query-Validation
enum<string>

Opt into strict query-name validation. The default is compatible: unknown names are ignored and reported in X-Query-Ignored. With strict, an unknown name returns 400 bad_request with error.reason unknown_query_parameter before the handler runs, including when its percent escape is incomplete.

Available options:
strict

Path Parameters

id
integer<int64>
required

Webhook endpoint id owned by the authenticated API key user.

Query Parameters

cursor
string

Opaque pagination cursor returned as next_cursor by a prior response. Omit to fetch the newest page.

limit
integer
default:20

Maximum delivery rows to return per page. Out-of-range values are clamped to 1..100.

Required range: 1 <= x <= 100

Response

Webhook delivery log page

object
string
required
Allowed value: "list"
data
object[]
required
has_more
boolean
required
meta
object
required
next_cursor
string
total
integer