---
title: "openemail.webhooks"
description: "Every method in this namespace: its signature, its parameters, what it returns and an example."
url: "https://openemail.uk/docs/sdk/reference/webhooks"
area: "SDK"
category: "Reference"
---

# openemail.webhooks

Every method in this namespace: its signature, its parameters, what it returns and an example.

## Methods

Endpoints that receive signed mailbox events, their secrets and their delivery log.

### `webhooks.list()`

List the webhook endpoints in the workspace

```ts
list(options?: ListOptions): Promise<Page<WebhookResource>>
```

Resolves one page of the webhook endpoints registered on the key's workspace, newest first. `listAll` collects every page and `iterate` walks them lazily.

Signing secrets are never part of a read. Only `create` and `rotateSecret` return `secret`, so a lost secret cannot be recovered from here. An endpoint subscribed to every event, which is what an endpoint created without `eventTypes` is, reports `eventTypes` as `['*']` rather than an empty array.

Read `enabled`, `disabledReason` and `consecutiveFailures` as the health summary. An endpoint the server switched off after 100 consecutive failed deliveries shows `enabled: false` with `disabledAt` and a reason, while one you disabled yourself through `update` has both of those null.

Scopes: `webhooks:read`.

**Parameters**

- `options.limit` (`number`): Page size, from 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): The `nextCursor` of the previous page. Leave it out for the first page.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`Page<WebhookResource>` with `items`, `hasMore` and `nextCursor`. Each item has `id`, `url`, `description`, `eventTypes`, `enabled`, `disabledAt`, `disabledReason`, `consecutiveFailures`, `addressAllowlist`, `domainAllowlist`, `lastDeliveryAt` and `createdAt`.

**Example**

```ts
const hooks = await openemail.webhooks.listAll()

const unhealthy = hooks.filter((hook) => !hook.enabled || hook.consecutiveFailures > 0)

console.log(unhealthy.map((hook) => [hook.url, hook.disabledReason]))
```

**Notes**

- A narrowed key reads every endpoint, and may write one whose own `addressAllowlist` and `domainAllowlist` sit inside what the key holds. A write that would take an endpoint wider than the key is 422 `capability_unsupported` on `addressAllowlist`.
- `lastDeliveryAt` moves on failed attempts as well as successful ones, so it shows the endpoint is being called, not that it is healthy.
- The cursor is opaque and holds where the last row sat in this order, so a row deleted or edited between pages never breaks the walk: the next page starts at the first row that sorts after it. A cursor this list did not hand out is a 400 `invalid_cursor`.

Also available in: API [`GET /webhooks`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks); CLI [`openemail webhooks list`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-list).

### `webhooks.listAll()`

Collect every webhook endpoint into one array

```ts
listAll(options?: ListOptions): Promise<Array<WebhookResource>>
```

Walks every page of `list` and resolves with all webhook endpoints, newest first. One request per page.

Scopes: `webhooks:read`.

**Parameters**

- `options.limit` (`number`): Page size for each request, from 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): Starts the walk after this cursor instead of the first page.
- `options.signal` (`AbortSignal`): Cancels the request in flight and the walk with it.
- `options.apiKey` (`string`): Overrides the client API key for every page of this walk.

**Returns**

`Array<WebhookResource>` holding every webhook endpoint.

**Example**

```ts
const all = await openemail.webhooks.listAll({ limit: 100 })

console.log(all.length)
```

**Notes**

- If any page fails the promise rejects and the webhook endpoints already fetched are discarded.

Also available in: API [`GET /webhooks`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks).

### `webhooks.iterate()`

Stream the webhook endpoints one at a time

```ts
iterate(options?: ListOptions): AsyncGenerator<WebhookResource, void, undefined>
```

Returns an async generator that yields webhook endpoints individually, newest first, and requests the next page only once the current one is drained. Nothing is fetched until you consume it, and breaking out of the loop stops the requests.

Scopes: `webhooks:read`.

**Parameters**

- `options.limit` (`number`): Page size for each request, from 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): Starts the walk after this cursor instead of the first page.
- `options.signal` (`AbortSignal`): Cancels the request in flight and the walk with it.
- `options.apiKey` (`string`): Overrides the client API key for every page of this walk.

**Returns**

`AsyncGenerator<WebhookResource, void, undefined>` yielding one webhook endpoint per step.

**Example**

```ts
for await (const item of openemail.webhooks.iterate()) {
    console.log(item)
}
```

**Notes**

- The generator is lazy, so an abandoned loop costs only the pages you consumed.

Also available in: API [`GET /webhooks`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks).

### `webhooks.get()`

Read one webhook endpoint by id

```ts
get(id: string, options?: RequestScope): Promise<WebhookResource>
```

Resolves a single endpoint with its URL, subscription list, enabled state and delivery health. The signing secret is never part of a read. It appears only in the responses of `create` and `rotateSecret`, and a lost one is replaced with `rotateSecret` rather than read back.

An id from another workspace answers exactly like one that never existed, with 404 `resource_not_found`, so a 404 does not tell you whether the endpoint was deleted or was never yours.

`consecutiveFailures` resets to 0 on any successful delivery and when `update` sets `enabled` to true. When it reaches 100 the server disables the endpoint, fills in `disabledAt` and `disabledReason`, and emails the workspace owner and every member whose role can read webhooks.

Scopes: `webhooks:read`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`WebhookResource` with `id`, `url`, `description`, `eventTypes`, `enabled`, `disabledAt`, `disabledReason`, `consecutiveFailures`, `addressAllowlist`, `domainAllowlist`, `lastDeliveryAt` and `createdAt`. No secret.

**Example**

```ts
const hook = await openemail.webhooks.get('whe_3f9c2a7b1e4d8f60a5c7b92d')

if (!hook.enabled && hook.disabledReason) {
    console.log(hook.disabledAt, hook.disabledReason)
}
```

**Notes**

- `eventTypes` of `['*']` means the endpoint named none, so it receives the default `email.*` set. `email.replied`, `domain.*`, `suppression.*`, `file.*` and `form.*` sit outside that set and have to be named explicitly.
- A GET is retried automatically on network failure and on 408, 429 and 5xx responses, up to the client `maxRetries`.

Also available in: API [`GET /webhooks/{id}`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-id); CLI [`openemail webhooks get`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-get).

### `webhooks.create()`

Register an HTTPS endpoint for mailbox events

```ts
create(body: WebhookCreate, options?: RequestScope): Promise<CreatedWebhookResource>
```

Registers a receiver URL and subscribes it to events on the key's workspace. The endpoint starts enabled, so the next matching event is delivered to it straight away. Leave `eventTypes` out, or pass an empty array, and the endpoint receives the default set, which is the `email.*` events other than `email.replied`. Every family outside it has to be named: `email.replied`, `domain.*`, `suppression.*`, `file.*` and `form.*`. Reads report an unnamed subscription as `['*']`.

By default an endpoint hears about every address the workspace owns. `addressAllowlist` and `domainAllowlist` narrow it, exactly as the same two lists narrow an API key: name whole domains, single addresses, or both. An event reaches the endpoint when the address or domain it concerns is covered. Events that name no address at all, such as `suppression.removed`, reach every endpoint whatever its lists say. `form.*` is the exception: a sign-up belongs to the whole workspace, so an endpoint limited to some addresses or domains never receives `form.submitted` or `form.confirmed`.

This response is the only place the full `secret` ever appears. Every later read omits it, so store it before doing anything else, and if it is lost call `rotateSecret`. The secret is `whsec_` followed by 43 base64url characters, and the HMAC key is the whole string including the prefix, so pass it to `verifyWebhookSignature` exactly as returned.

`url` must be https. `localhost`, hosts ending `.localhost`, `.internal` or `.local`, and IP literals in loopback, private, link local, carrier grade NAT, multicast or unique local ranges are refused with 422 `invalid_webhook_url`. The host is resolved again on every delivery, and an attempt to a name that resolves into one of those ranges is recorded as failed without being sent. Deliveries never follow redirects, so register the final address.

Scopes: `webhooks:write`.

**Parameters**

- `body.url` (`string`, required): The https receiver URL. Another scheme or a blocked host is 422 `invalid_webhook_url`. Stored in normalised form, so the `url` read back can differ cosmetically.
- `body.eventTypes` (`Array<WebhookEvent>`): Events to subscribe to. Omit it, or send `[]`, for the default `email.*` set: `email.received`, `email.sent`, `email.failed`, `email.cancelled`, `email.scheduled`, `email.queued`, `email.delivered`, `email.delivery_delayed`, `email.bounced`, `email.complained`, `email.suppressed`, `email.opened`, `email.clicked` and `email.downloaded`. `email.replied`, `domain.verified`, `domain.sending_changed`, `domain.deleted`, `suppression.added`, `suppression.removed`, `file.uploaded`, `file.deleted`, `form.submitted` and `form.confirmed` are outside that set and have to be named.
- `body.description` (`string`): Free text note, at most 200 characters.
- `body.addressAllowlist` (`Array<string>`): Single addresses this endpoint hears about. An event is delivered when the address it concerns is on this list, or when its domain is in `domainAllowlist`. Leave both empty and the endpoint hears about every address the workspace owns. At most 50, and an address this workspace does not own is 422 `invalid_parameter`.
- `body.domainAllowlist` (`Array<string>`): Whole domains this endpoint hears about, including addresses added to them later. A domain also carries its own `domain.*` events. At most 25. An address whose domain is already listed here is dropped from `addressAllowlist` when the endpoint is saved, so the two lists never overlap.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`CreatedWebhookResource`, a `WebhookResource` plus the plaintext `secret`. Alongside it you get `id`, `url`, `description`, `eventTypes`, `enabled`, `disabledAt`, `disabledReason`, `consecutiveFailures`, `addressAllowlist`, `domainAllowlist`, `lastDeliveryAt` and `createdAt`.

**Example**

```ts
const hook = await openemail.webhooks.create({
    url: 'https://hooks.acme.com/openemail',
    eventTypes: ['email.received', 'email.bounced', 'email.complained'],
    description: 'Support desk sync'
})

console.log(hook.secret)
console.log(hook.id, hook.eventTypes)
```

**Notes**

- Verify each delivery with `verifyWebhookSignature({ payload, headers, secret })` from the package root, passing the raw request body. It checks the `X-OpenEmail-Signature` HMAC-SHA256 over the timestamp, a dot and the raw body in constant time, rejects a timestamp more than 300 seconds off, throws on failure and returns `{ id, type, createdAt, data }`.
- Each attempt is one POST with a 5 second timeout. A failure worth repeating (no answer, 408, 425, 429 or a 5xx) is tried again after 1 minute, 5 minutes, 30 minutes, 2 hours, 5 hours, 10 hours and 10 hours, up to 8 attempts over about 27 and a half hours, each wait varied by up to 10% and stretched when your server's `Retry-After` asks for longer, up to 6 hours. A 410 Gone switches the endpoint off. `listDeliveries` shows every attempt with its number, and `replayDelivery` sends one of them again, one event at a time, once your receiver is fixed.
- A workspace holds 10 endpoints by default, and support can raise that for a workspace that needs more. The next one past the limit is 422 `workspace_limit_reached`. A narrowed key may create an endpoint, but only one whose own lists sit inside what the key holds; anything wider is 422 `capability_unsupported` on `addressAllowlist`.
- Not retried automatically, so a network failure can leave an endpoint created with a secret you never saw. Check `list` before creating it again.

Also available in: API [`POST /webhooks`](https://openemail.uk/docs/api/reference/webhooks#post-webhooks); CLI [`openemail webhooks create`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-create).

### `webhooks.update()`

Change an endpoint URL, events or enabled state

```ts
update(id: string, patch: WebhookPatch, options?: RequestScope): Promise<WebhookResource>
```

Patches the URL, subscription list, description or enabled flag of one endpoint. Every field is optional, and an empty patch is accepted and changes nothing you can read back. A new `url` goes through the same https and host checks as `create`, and `description: null` clears the note.

`eventTypes` replaces the subscription set wholesale, so send the complete list you want rather than a delta. An empty array does not unsubscribe: it puts the endpoint back on the default `email.*` set. To stop deliveries, set `enabled` to false instead.

`addressAllowlist` and `domainAllowlist` replace the endpoint's scope the same way, wholesale rather than as a delta. Send both empty to widen it back to every address the workspace owns. Each list is checked against the domains and addresses this workspace actually owns, and an unknown one is 422 `invalid_parameter`.

Writing `enabled` clears `disabledAt` and `disabledReason` either way, so an endpoint you switch off yourself reports both as null. Setting it back to true also resets `consecutiveFailures` to 0, which is how an endpoint the server disabled after 100 failures is brought back. Events that fire while an endpoint is disabled are never delivered to it later, but a delivery that failed before it was switched off can be sent again with `replayDelivery` once it is back on, one event at a time.

Scopes: `webhooks:write`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `patch.url` (`string`): Replacement https URL, checked against the same host rules as `create`.
- `patch.eventTypes` (`Array<WebhookEvent>`): Complete replacement subscription set. `[]` means the default `email.*` set.
- `patch.addressAllowlist` (`Array<string>`): Complete replacement list of single addresses this endpoint hears about. At most 50. Send `[]` on both lists to hear about every address again.
- `patch.domainAllowlist` (`Array<string>`): Complete replacement list of whole domains this endpoint hears about, including addresses added to them later. At most 25.
- `patch.description` (`string | null`): Replacement note of at most 200 characters, or null to clear it.
- `patch.enabled` (`boolean`): False stops deliveries. True resumes them and resets `consecutiveFailures`.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`WebhookResource` as saved. The signing secret is untouched and not included.

**Example**

```ts
const updated = await openemail.webhooks.update('whe_3f9c2a7b1e4d8f60a5c7b92d', {
    eventTypes: ['email.sent', 'email.bounced', 'email.complained'],
    enabled: true
})

console.log(updated.eventTypes, updated.consecutiveFailures)
```

**Notes**

- Read the current `eventTypes` first if you mean to add one, since a partial list silently unsubscribes the rest. The same applies to the two allowlists. Do not send back `['*']` as read: it is a 422 `invalid_parameter`, and `[]` is how to ask for the default set.
- This route never touches the signing secret. Use `rotateSecret` for that.
- Retried automatically on network failure and retryable statuses, since the same patch applied twice lands on the same row.

Also available in: API [`PATCH /webhooks/{id}`](https://openemail.uk/docs/api/reference/webhooks#patch-webhooks-id); CLI [`openemail webhooks update`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-update).

### `webhooks.delete()`

Delete an endpoint and its delivery log

```ts
delete(id: string, options?: RequestScope): Promise<DeletedWebhookResource>
```

Removes the endpoint for good. Deliveries stop immediately, the signing secret is gone, and the delivery log for the endpoint is deleted with it, so read it with `listAllDeliveries` first if you need it for an audit trail.

There is no undo and no soft delete. If the aim is only to pause deliveries, call `update` with `enabled: false` and keep the endpoint, its secret and its log.

The response is a tombstone rather than an empty body, so a log line can name what went. Deleting frees a slot against the workspace's endpoint limit straight away.

Scopes: `webhooks:write`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`DeletedWebhookResource` with `object` set to `webhook`, the `id` and `deleted: true`.

**Example**

```ts
const log = await openemail.webhooks.listAllDeliveries('whe_3f9c2a7b1e4d8f60a5c7b92d')

const removed = await openemail.webhooks.delete('whe_3f9c2a7b1e4d8f60a5c7b92d')

console.log(log.length, removed.deleted)
```

**Notes**

- Not idempotent: a second call on the same id is 404 `resource_not_found`, and the SDK does not retry it after a network failure.
- A narrowed key may delete only an endpoint whose own allowlists sit inside what the key holds; any other is 422 `capability_unsupported` on `addressAllowlist`.

Also available in: API [`DELETE /webhooks/{id}`](https://openemail.uk/docs/api/reference/webhooks#delete-webhooks-id); CLI [`openemail webhooks delete`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-delete).

### `webhooks.rotateSecret()`

Issue a new signing secret for an endpoint

```ts
rotateSecret(id: string, options?: RequestScope): Promise<CreatedWebhookResource>
```

Generates a new signing secret and resolves with the endpoint plus the new plaintext `secret`. As with `create`, this response is the only place that secret appears, so store it before anything else.

There is no overlap window. Every delivery is signed at send time with the current secret, so the old one stops verifying the moment this call commits, and any event that fires before your receiver has the new secret fails verification on your side.

The safe order is to deploy a receiver that tries both the old secret and a new one read from config, call this, write the returned secret to config, then drop the old one. `test` confirms the new secret verifies before you remove the fallback.

Scopes: `webhooks:write`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`CreatedWebhookResource`: the full `WebhookResource` plus the new `secret`, formatted `whsec_` followed by 43 base64url characters.

**Example**

```ts
const rotated = await openemail.webhooks.rotateSecret('whe_3f9c2a7b1e4d8f60a5c7b92d')

console.log(rotated.secret)

const check = await openemail.webhooks.test(rotated.id)

console.log(check.delivery?.status)
```

**Notes**

- There is no request body and the success status is 200, not 201.
- Not retried automatically. A lost response means a secret you never saw is already live, so rotate again rather than waiting.
- Subscriptions, enabled state and `consecutiveFailures` are left as they were.

Also available in: API [`POST /webhooks/{id}/rotate-secret`](https://openemail.uk/docs/api/reference/webhooks#post-webhooks-id-rotate-secret); CLI [`openemail webhooks rotate-secret`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-rotate-secret).

### `webhooks.test()`

Send a synthetic event and report how delivery went

```ts
test(id: string, options?: RequestScope): Promise<WebhookTestResource>
```

Posts a signed synthetic `email.sent` event to the endpoint and waits for the attempt to finish before resolving. The payload `data` is `{ test: true, note }` and no mail is sent, so it is safe against a production receiver. It proves the URL is reachable and that your signature check accepts the current secret before real mail depends on it.

The outcome comes back as `delivery`, read from the newest row of the delivery log. `status` is `delivered` for any 2xx answer and `failed` otherwise, `responseCode` is the HTTP status or null when no response arrived, such as a DNS failure or the 5 second timeout, and `error` explains a failure. A 3xx counts as failed because redirects are never followed.

The event goes out whatever the endpoint subscribes to, and even when it is disabled. It is recorded like any delivery, so it appears in `listDeliveries` and can be sent again with `replayDelivery`, but it is tried once and leaves `consecutiveFailures` and `lastDeliveryAt` alone, so a failing test never counts toward the 100 that disable an endpoint. A 410 Gone answer does switch the endpoint off, as it would for a real event.

Scopes: `webhooks:write`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`WebhookTestResource` with `object` set to `webhook_test`, the endpoint `id`, and `delivery` holding `status`, `responseCode`, `durationMs` and `error`, or null when no delivery row could be read back.

**Example**

```ts
const result = await openemail.webhooks.test('whe_3f9c2a7b1e4d8f60a5c7b92d')

if (result.delivery?.status !== 'delivered') {
    console.log(result.delivery?.responseCode, result.delivery?.error)
}
```

**Notes**

- The call resolves with 200 when your receiver fails. Branch on `delivery.status`, not on whether the promise rejected.
- A 4xx from your receiver is a useful answer: the URL is reachable and the rejection came from your own handler, often its signature check.
- Not retried automatically, since every call sends another request to your receiver.
- If a real event reaches the same endpoint at the same moment, `delivery` can describe that attempt instead, because it reads the newest log row.

Also available in: API [`POST /webhooks/{id}/test`](https://openemail.uk/docs/api/reference/webhooks#post-webhooks-id-test); CLI [`openemail webhooks test`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-test).

### `webhooks.listDeliveries()`

List one page of delivery attempts for one endpoint

```ts
listDeliveries(id: string, options?: WebhookDeliveryListOptions): Promise<Page<WebhookDeliveryResource>>
```

Returns one page of an endpoint's delivery log, newest first. Nothing is dropped from the log, so following `nextCursor` while `hasMore` is true reaches the endpoint's very first delivery, and `listAllDeliveries` and `iterateDeliveries` do that walk for you. `status`, `since` and `until` narrow it the way the Deliveries tab of the app does: `status: 'failed'` is its "only failed" switch.

Each attempt is one POST with a 5 second timeout, and one event can appear several times: when the failure is worth repeating, a delivery is tried up to 8 times, as it happens and then after 1 minute, 5 minutes, 30 minutes, 2 hours, 5 hours, 10 hours and 10 hours, about 27 and a half hours in all, and each `replayDelivery` adds a row of its own. `attempt` and `maxAttempts` say which try a row is, and `eventId` is the same across all of them, so this log distinguishes a retry from a new event. `nextAttemptAt` is when the automatic retry that follows a row is due, and null when none is waiting, so a failed row with a time in it is not the final word. `status` is `delivered` for a 2xx answer and `failed` for anything else, including a 3xx, since redirects are not followed.

`responseCode` null means no response arrived, such as a DNS or TLS failure or the timeout, which is a different fact from a receiver that answered. `durationMs` is null only when the attempt was never made because the server could not read the signing secret, and `error` then says so. The body that was sent and your server's answer are not part of this response, and `getDelivery` returns both. `listWorkspaceDeliveries` reads every endpoint at once.

Scopes: `webhooks:read`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `options.status` (`'delivered' | 'failed'`): `failed` keeps only the attempts that did not get a 2xx, the "only failed" view of the app; `delivered` keeps the rest.
- `options.since` (`Date | string`): Only rows at or after this instant. A `Date` is sent as ISO 8601, and a string must already be one.
- `options.until` (`Date | string`): Only rows before this instant. It has to be later than `since`, or the server answers 400 `invalid_parameter`.
- `options.limit` (`number`): Rows per page, a whole number from 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): The `nextCursor` from the previous page, passed back unchanged. Never build one yourself.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`Page<WebhookDeliveryResource>` with `items`, `hasMore` and `nextCursor`. Each item has `id`, `endpointId`, `eventType`, `eventId`, `status`, `responseCode`, `durationMs`, `attempt`, `maxAttempts`, `error`, `createdAt` and `nextAttemptAt`.

**Example**

```ts
const page = await openemail.webhooks.listDeliveries('whe_3f9c2a7b1e4d8f60a5c7b92d', {
    status: 'failed',
    since: new Date(Date.now() - 24 * 60 * 60 * 1000),
    limit: 50
})

console.log(page.items.map((delivery) => [delivery.eventType, delivery.responseCode, delivery.error]))
console.log(page.hasMore, page.nextCursor)
```

**Notes**

- Synthetic events from `test` appear here too, recorded as `email.sent`.
- Each endpoint's copy of an event gets its own `evt_` id, sent in the `X-OpenEmail-Delivery` header and as the payload `id`, and every retry and replay of that copy keeps it. One event fanned out to two endpoints arrives with two different ids, and a repeat to one endpoint arrives with the same one.
- The cursor stays valid under every filter as long as each page sends the same `status`, `since` and `until`, which `listAll…` and `iterate…` do for you.
- A 404 `resource_not_found` means the endpoint id is wrong or belongs to another workspace, not that the log is empty. A cursor that names no delivery of this endpoint is a 400 `invalid_cursor`, and a `since` or `until` that does not parse is a 400 `invalid_parameter`.

Also available in: API [`GET /webhooks/{id}/deliveries`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-id-deliveries); CLI [`openemail webhooks list-deliveries`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-list-deliveries).

### `webhooks.listAllDeliveries()`

Collect an endpoint's whole delivery log into one array

```ts
listAllDeliveries(id: string, options?: WebhookDeliveryListOptions): Promise<Array<WebhookDeliveryResource>>
```

Walks every page of an endpoint's delivery log and resolves with all of its attempts, newest first, under the same `status`, `since` and `until` filters as `listDeliveries`. The log is never pruned, so an endpoint that has been busy for a long time can hold a great many rows; narrow it with a window, or prefer `iterateDeliveries` when you can stop early.

Pages are keyset on `createdAt` and `id`, walking backwards in time. Attempts recorded after the walk starts are newer than its first page and are not included.

Scopes: `webhooks:read`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `options.status` (`'delivered' | 'failed'`): `failed` keeps only the attempts that did not get a 2xx, the "only failed" view of the app; `delivered` keeps the rest.
- `options.since` (`Date | string`): Only rows at or after this instant. A `Date` is sent as ISO 8601, and a string must already be one.
- `options.until` (`Date | string`): Only rows before this instant. It has to be later than `since`, or the server answers 400 `invalid_parameter`.
- `options.limit` (`number`): Page size for each request, 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): Starts the walk from this cursor instead of the newest row.
- `options.signal` (`AbortSignal`): Cancels the request in flight and the walk with it.
- `options.apiKey` (`string`): Overrides the client API key for every page of this walk.

**Returns**

`Array<WebhookDeliveryResource>` holding every matching attempt on the endpoint, newest first.

**Example**

```ts
const failures = await openemail.webhooks.listAllDeliveries('whe_3f9c2a7b1e4d8f60a5c7b92d', { status: 'failed', limit: 100 })

const failedEvents = new Set(failures.map((delivery) => delivery.eventId))

console.log(`${failedEvents.size} events had a failed attempt`)
```

**Notes**

- If any page fails the promise rejects and the attempts already fetched are discarded.
- One request per page, so a large log takes many requests. Read it with `iterateDeliveries` to stop as soon as you have what you need.

Also available in: API [`GET /webhooks/{id}/deliveries`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-id-deliveries).

### `webhooks.iterateDeliveries()`

Stream an endpoint's delivery attempts one at a time, newest first

```ts
iterateDeliveries(id: string, options?: WebhookDeliveryListOptions): AsyncGenerator<WebhookDeliveryResource, void, undefined>
```

Returns an async generator over an endpoint's delivery log that yields attempts individually and fetches the next page only when the current one is drained, under the same `status`, `since` and `until` filters as `listDeliveries`. Nothing is requested until you consume it, and breaking out of the loop stops further requests, which makes it the right way to find the latest attempt of some kind without reading the whole history.

The walk ends when `hasMore` is false, when a page comes back empty, or when the server repeats a cursor. Attempts recorded after the walk starts are newer than its cursor and are not yielded.

Scopes: `webhooks:read`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `options.status` (`'delivered' | 'failed'`): `failed` keeps only the attempts that did not get a 2xx, the "only failed" view of the app; `delivered` keeps the rest.
- `options.since` (`Date | string`): Only rows at or after this instant. A `Date` is sent as ISO 8601, and a string must already be one.
- `options.until` (`Date | string`): Only rows before this instant. It has to be later than `since`, or the server answers 400 `invalid_parameter`.
- `options.limit` (`number`): Page size per request, 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): Starts the walk from this cursor instead of the newest row.
- `options.signal` (`AbortSignal`): Cancels the request in flight and ends the iteration.
- `options.apiKey` (`string`): Overrides the client API key for every page of this walk.

**Returns**

`AsyncGenerator<WebhookDeliveryResource, void, undefined>` yielding one attempt per step.

**Example**

```ts
for await (const delivery of openemail.webhooks.iterateDeliveries('whe_3f9c2a7b1e4d8f60a5c7b92d', { status: 'failed' })) {
    if (delivery.nextAttemptAt === null) {
        console.log(delivery.createdAt, delivery.eventType, delivery.responseCode, delivery.error)
        break
    }
}
```

**Notes**

- An aborted `options.signal` rejects the pending page request, which throws out of the `for await` loop.

Also available in: API [`GET /webhooks/{id}/deliveries`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-id-deliveries).

### `webhooks.getDelivery()`

Read one delivery attempt in full, with the body that was sent

```ts
getDelivery(id: string, deliveryId: string, options?: RequestScope): Promise<WebhookDeliveryDetailResource>
```

Resolves one attempt from an endpoint's delivery log with what `listDeliveries` leaves out. `payload` is the exact JSON body that was POSTed, `{ id, type, createdAt, data }`, and `responseBody` is the first 2,000 characters your server answered, or null when nothing came back or the answer was a redirect.

`attempts` lists every try of the same event on this endpoint, oldest first: the first attempt, the automatic retries and any replays, each with its own `id`, `attempt`, `status`, `responseCode`, `error` and `createdAt`. They share `eventId`, which is the payload `id` your receiver saw. `nextAttemptAt` is when the next automatic retry of the event is due, whichever attempt it follows, and null when none is waiting.

`replayRefusal` says whether `replayDelivery` would accept this attempt before you call it: null when it would, and otherwise the `code` and `message` the replay would be refused with, such as `webhook_disabled` while the endpoint is switched off, or `retry_in_progress` while an automatic retry of the same event is being sent.

Scopes: `webhooks:read`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `deliveryId` (`string`, required): Delivery id, `whd_` followed by 24 hex characters, as `listDeliveries` returns it.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`WebhookDeliveryDetailResource`: the `WebhookDeliveryResource` fields (`id`, `eventType`, `eventId`, `status`, `responseCode`, `durationMs`, `attempt`, `maxAttempts`, `error`, `createdAt`, `nextAttemptAt`) plus `endpointId`, `payload`, `responseBody`, `attempts` and `replayRefusal`.

**Example**

```ts
const detail = await openemail.webhooks.getDelivery('whe_3f9c2a7b1e4d8f60a5c7b92d', 'whd_8c1e4a7f2b9d3e6a0c5f1b28')

console.log(detail.payload?.type, detail.responseCode, detail.responseBody)
console.log(detail.attempts.map((attempt) => [attempt.attempt, attempt.status, attempt.responseCode]))

if (detail.replayRefusal) console.log(detail.replayRefusal.code, detail.replayRefusal.message)
```

**Notes**

- A delivery id that belongs to another endpoint, even one in the same workspace, is 404 `resource_not_found`, exactly like one that never existed.
- Your server's answer is cut at 2,000 characters when it is recorded, so a longer one reads back truncated.
- A GET is retried automatically on network failure and on 408, 429 and 5xx responses, up to the client `maxRetries`.
- A narrowed key may read a delivery only on an endpoint whose own allowlists sit inside what the key holds, where holding one address never covers its whole domain, because the body names the addresses the event is about; any other is 422 `capability_unsupported` on `addressAllowlist`. Over OAuth only the workspace owner, or a member whose role holds `addresses:all`, may read one, and any other member's token is 403 `owner_only`. That member's token is held to the domains the workspace has now, so it reads only a delivery of an endpoint with allowlists, and one with none is 422 `capability_unsupported` for it too.

Also available in: API [`GET /webhooks/{id}/deliveries/{deliveryId}`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-id-deliveries-deliveryid); CLI [`openemail webhooks get-delivery`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-get-delivery).

### `webhooks.replayDelivery()`

Send one stored event to the endpoint again, now

```ts
replayDelivery(id: string, deliveryId: string, options?: RequestScope): Promise<WebhookReplayResource>
```

Posts the event behind a recorded attempt to the endpoint once more, straight away, and resolves when that attempt has finished. The body is the one stored with the original, with the same `id`, `type`, `createdAt` and `data`, so a receiver that drops ids it has already handled treats the replay as the event it already knows. Only `X-OpenEmail-Signature` is new, because every POST is signed with the current secret at the moment it goes out, so a replay verifies after a `rotateSecret` too.

It accepts a delivered attempt as well as a failed one. Replaying a success is how a receiver that lost its copy, or handled it wrongly, is brought back in step. Any attempt of the event will do, since they all carry the same event.

The replay is recorded in the log as a new delivery, attempt 1 of 1, and is never retried automatically. Before it goes out, the automatic retries of the same event that have not started are paused, so the receiver never gets two copies at once. When the replay is delivered they stay cancelled; when it fails they resume on their schedule. If an automatic retry of the event is being sent at that very moment, the replay sends nothing and is refused with 409 `retry_in_progress`, and if another replay of the same event is still being sent, it is refused with 409 `replay_in_progress`, so two copies never go out at once. The call resolves with 200 whatever your server answered, so branch on `delivery.status` rather than on whether the promise rejected.

Scopes: `webhooks:write`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `deliveryId` (`string`, required): Any attempt of the event to send again, `whd_` followed by 24 hex characters.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`WebhookReplayResource` with `object` set to `webhook_replay`, `id` (the new delivery), `endpointId`, `replayOf` (the attempt you named), `eventId`, `eventType`, and `delivery` holding `status`, `responseCode`, `durationMs` and `error`.

**Example**

```ts
const replay = await openemail.webhooks.replayDelivery('whe_3f9c2a7b1e4d8f60a5c7b92d', 'whd_8c1e4a7f2b9d3e6a0c5f1b28')

if (replay.delivery.status !== 'delivered') {
    console.log(replay.delivery.responseCode, replay.delivery.error)
}
```

**Notes**

- Refused with 409 when nobody who wants the event would receive it: `webhook_disabled` while the endpoint is switched off, `event_not_subscribed` when it no longer listens for the event type, `event_out_of_scope` when its allowlists no longer cover the address the event is about, `delivery_not_replayable` when the attempt has no stored event, `retry_in_progress` while an automatic retry of the same event is being sent, and `replay_in_progress` while another replay of it is. Wait a few seconds and check `getDelivery` before replaying again, since that retry or replay may deliver it. `getDelivery` reports the same answer in advance as `replayRefusal`. A synthetic event from `test` replays whatever the endpoint subscribes to.
- Not retried automatically, because a retry after a lost response would send the event again. A receiver that drops repeated ids handles that safely, but the SDK does not assume yours does.
- A delivered replay resets `consecutiveFailures`, and a failed one does not add to it. A 410 Gone switches the endpoint off, as it does for an automatic delivery.
- A narrowed key may replay only on an endpoint whose own allowlists sit inside what the key holds; any other is 422 `capability_unsupported` on `addressAllowlist`.

Also available in: API [`POST /webhooks/{id}/deliveries/{deliveryId}/replay`](https://openemail.uk/docs/api/reference/webhooks#post-webhooks-id-deliveries-deliveryid-replay); CLI [`openemail webhooks replay-delivery`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-replay-delivery).

### `webhooks.listWorkspaceDeliveries()`

List one page of delivery attempts across every endpoint

```ts
listWorkspaceDeliveries(options?: WebhookWorkspaceDeliveryListOptions): Promise<Page<WebhookDeliveryResource>>
```

Returns one page of the whole workspace's delivery log, newest first: the all-endpoints Deliveries tab of the app. Each row carries `endpointId`, so the endpoint an attempt went to is never lost. `endpointIds` narrows it to some endpoints, and `status`, `since` and `until` work exactly as they do on `listDeliveries`.

Nothing is pruned, so following `nextCursor` while `hasMore` is true reaches the workspace's first delivery; `listAllWorkspaceDeliveries` and `iterateWorkspaceDeliveries` do that walk. The body that was sent is not here: read it with `getDelivery`, passing the row's `endpointId` and `id`.

Scopes: `webhooks:read`.

**Parameters**

- `options.endpointIds` (`Array<string>`): Endpoint ids to read, at most 50, sent comma-separated. Left out, every endpoint in the workspace.
- `options.status` (`'delivered' | 'failed'`): `failed` keeps only the attempts that did not get a 2xx, the "only failed" view of the app; `delivered` keeps the rest.
- `options.since` (`Date | string`): Only rows at or after this instant. A `Date` is sent as ISO 8601, and a string must already be one.
- `options.until` (`Date | string`): Only rows before this instant. It has to be later than `since`, or the server answers 400 `invalid_parameter`.
- `options.limit` (`number`): Rows per page, a whole number from 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): The `nextCursor` from the previous page, passed back unchanged. Never build one yourself.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`Page<WebhookDeliveryResource>` with `items`, `hasMore` and `nextCursor`. Each item has `id`, `endpointId`, `eventType`, `eventId`, `status`, `responseCode`, `durationMs`, `attempt`, `maxAttempts`, `error`, `createdAt` and `nextAttemptAt`.

**Example**

```ts
const page = await openemail.webhooks.listWorkspaceDeliveries({ status: 'failed', limit: 50 })

for (const delivery of page.items) {
    console.log(delivery.endpointId, delivery.eventType, delivery.responseCode)
}
```

**Notes**

- An endpoint id in `endpointIds` that belongs to no endpoint here simply matches nothing. A removed endpoint takes its deliveries with it.
- The cursor stays valid under every filter as long as each page sends the same `endpointIds`, `status`, `since` and `until`, which `listAll…` and `iterate…` do for you.
- The list carries no payloads, so a key narrowed to some addresses may read it; opening a delivery with `getDelivery` is where the narrowing applies.

Also available in: API [`GET /webhooks/deliveries`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-deliveries); CLI [`openemail webhooks list-workspace-deliveries`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-list-workspace-deliveries).

### `webhooks.listAllWorkspaceDeliveries()`

Collect the workspace's whole delivery log into one array

```ts
listAllWorkspaceDeliveries(options?: WebhookWorkspaceDeliveryListOptions): Promise<Array<WebhookDeliveryResource>>
```

Walks every page of `listWorkspaceDeliveries` under the same filters and resolves with every matching attempt, newest first. The log is never pruned, so give it a `since` or `endpointIds` unless you mean to read all of it, or use `iterateWorkspaceDeliveries` to stop early.

Scopes: `webhooks:read`.

**Parameters**

- `options.endpointIds` (`Array<string>`): Endpoint ids to read, at most 50, sent comma-separated. Left out, every endpoint in the workspace.
- `options.status` (`'delivered' | 'failed'`): `failed` keeps only the attempts that did not get a 2xx, the "only failed" view of the app; `delivered` keeps the rest.
- `options.since` (`Date | string`): Only rows at or after this instant. A `Date` is sent as ISO 8601, and a string must already be one.
- `options.until` (`Date | string`): Only rows before this instant. It has to be later than `since`, or the server answers 400 `invalid_parameter`.
- `options.limit` (`number`): Page size for each request, 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): Starts the walk from this cursor instead of the newest row.
- `options.signal` (`AbortSignal`): Cancels the request in flight and the walk with it.
- `options.apiKey` (`string`): Overrides the client API key for every page of this walk.

**Returns**

`Array<WebhookDeliveryResource>` holding every matching attempt, newest first.

**Example**

```ts
const lastDay = await openemail.webhooks.listAllWorkspaceDeliveries({
    status: 'failed',
    since: new Date(Date.now() - 24 * 60 * 60 * 1000),
    limit: 100
})

console.log(`${lastDay.length} failed attempts in the last day`)
```

**Notes**

- If any page fails the promise rejects and the attempts already fetched are discarded.

Also available in: API [`GET /webhooks/deliveries`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-deliveries).

### `webhooks.iterateWorkspaceDeliveries()`

Stream the workspace's delivery attempts one at a time, newest first

```ts
iterateWorkspaceDeliveries(options?: WebhookWorkspaceDeliveryListOptions): AsyncGenerator<WebhookDeliveryResource, void, undefined>
```

An async generator over `listWorkspaceDeliveries` under the same filters. It fetches a page only when the one before is drained and stops requesting when you break out of the loop.

Scopes: `webhooks:read`.

**Parameters**

- `options.endpointIds` (`Array<string>`): Endpoint ids to read, at most 50, sent comma-separated. Left out, every endpoint in the workspace.
- `options.status` (`'delivered' | 'failed'`): `failed` keeps only the attempts that did not get a 2xx, the "only failed" view of the app; `delivered` keeps the rest.
- `options.since` (`Date | string`): Only rows at or after this instant. A `Date` is sent as ISO 8601, and a string must already be one.
- `options.until` (`Date | string`): Only rows before this instant. It has to be later than `since`, or the server answers 400 `invalid_parameter`.
- `options.limit` (`number`): Page size per request, 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): Starts the walk from this cursor instead of the newest row.
- `options.signal` (`AbortSignal`): Cancels the request in flight and ends the iteration.
- `options.apiKey` (`string`): Overrides the client API key for every page of this walk.

**Returns**

`AsyncGenerator<WebhookDeliveryResource, void, undefined>` yielding one attempt per step.

**Example**

```ts
for await (const delivery of openemail.webhooks.iterateWorkspaceDeliveries({ status: 'failed' })) {
    const detail = await openemail.webhooks.getDelivery(delivery.endpointId, delivery.id)
    if (detail.replayRefusal === null) console.log('replayable', delivery.id)
}
```

**Notes**

- An aborted `options.signal` rejects the pending page request, which throws out of the `for await` loop.

Also available in: API [`GET /webhooks/deliveries`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-deliveries).

### `webhooks.listActivity()`

List one page of what happened to one endpoint

```ts
listActivity(id: string, options?: WebhookActivityListOptions): Promise<Page<WebhookActivityResource>>
```

Returns one page of an endpoint's audit log, newest first, the Activity tab of the endpoint in the app. Every change is a row: `created`, `updated`, `enabled`, `disabled`, `auto_disabled`, `secret_rotated`, `tested`, `replayed` and `removed`, whether it came from the app, from a key over the API, or from OpenEmail itself. `actor` says who, with `label` already formatted the way the app shows it: `@username` for a person, `API key <name>` for a key, and `actor` is null when OpenEmail made the change on its own, such as switching an endpoint off after 100 failed events in a row. `detail` carries what moved: the URL, `previousUrl` when it changed, the event types and allowlists an update set, or the status and response code a test or a replay got.

Nothing is pruned, and a removed endpoint keeps its history, so this answers for an endpoint that is gone too. `since` and `until` keep a window.

Scopes: `webhooks:read`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `options.since` (`Date | string`): Only rows at or after this instant. A `Date` is sent as ISO 8601, and a string must already be one.
- `options.until` (`Date | string`): Only rows before this instant. It has to be later than `since`, or the server answers 400 `invalid_parameter`.
- `options.limit` (`number`): Rows per page, a whole number from 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): The `nextCursor` from the previous page, passed back unchanged. Never build one yourself.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`Page<WebhookActivityResource>` with `items`, `hasMore` and `nextCursor`. Each item has `id`, `endpointId`, `endpointLabel`, `type`, `createdAt`, `actor` and `detail`.

**Example**

```ts
const page = await openemail.webhooks.listActivity('whe_3f9c2a7b1e4d8f60a5c7b92d')

for (const change of page.items) {
    console.log(change.createdAt, change.type, change.actor?.label ?? 'OpenEmail')
}
```

**Notes**

- A 404 means no endpoint and no history with that id exists in this workspace. The cursor is opaque: pass `nextCursor` back as it came, and one this list did not hand out is a 400 `invalid_cursor`.

Also available in: API [`GET /webhooks/{id}/activity`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-id-activity); CLI [`openemail webhooks list-activity`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-list-activity).

### `webhooks.listAllActivity()`

Collect one endpoint's whole audit log into one array

```ts
listAllActivity(id: string, options?: WebhookActivityListOptions): Promise<Array<WebhookActivityResource>>
```

Walks every page of `listActivity` under the same window and resolves with every change, newest first.

Scopes: `webhooks:read`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `options.since` (`Date | string`): Only rows at or after this instant. A `Date` is sent as ISO 8601, and a string must already be one.
- `options.until` (`Date | string`): Only rows before this instant. It has to be later than `since`, or the server answers 400 `invalid_parameter`.
- `options.limit` (`number`): Page size for each request, 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): Starts the walk from this cursor instead of the newest row.
- `options.signal` (`AbortSignal`): Cancels the request in flight and the walk with it.
- `options.apiKey` (`string`): Overrides the client API key for every page of this walk.

**Returns**

`Array<WebhookActivityResource>`, newest first.

**Example**

```ts
const history = await openemail.webhooks.listAllActivity('whe_3f9c2a7b1e4d8f60a5c7b92d')

const rotations = history.filter((change) => change.type === 'secret_rotated')

console.log(rotations.map((change) => [change.createdAt, change.actor?.label]))
```

**Notes**

- If any page fails the promise rejects and the rows already fetched are discarded.

Also available in: API [`GET /webhooks/{id}/activity`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-id-activity).

### `webhooks.iterateActivity()`

Stream one endpoint's audit log one change at a time

```ts
iterateActivity(id: string, options?: WebhookActivityListOptions): AsyncGenerator<WebhookActivityResource, void, undefined>
```

An async generator over `listActivity` under the same window, fetching a page only when the one before is drained.

Scopes: `webhooks:read`.

**Parameters**

- `id` (`string`, required): Endpoint id, `whe_` followed by 24 hex characters.
- `options.since` (`Date | string`): Only rows at or after this instant. A `Date` is sent as ISO 8601, and a string must already be one.
- `options.until` (`Date | string`): Only rows before this instant. It has to be later than `since`, or the server answers 400 `invalid_parameter`.
- `options.limit` (`number`): Page size per request, 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): Starts the walk from this cursor instead of the newest row.
- `options.signal` (`AbortSignal`): Cancels the request in flight and ends the iteration.
- `options.apiKey` (`string`): Overrides the client API key for every page of this walk.

**Returns**

`AsyncGenerator<WebhookActivityResource, void, undefined>` yielding one change per step.

**Example**

```ts
for await (const change of openemail.webhooks.iterateActivity('whe_3f9c2a7b1e4d8f60a5c7b92d')) {
    if (change.type === 'auto_disabled') {
        console.log('switched off by OpenEmail at', change.createdAt, change.detail)
        break
    }
}
```

Also available in: API [`GET /webhooks/{id}/activity`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-id-activity).

### `webhooks.listWorkspaceActivity()`

List one page of what happened to every endpoint

```ts
listWorkspaceActivity(options?: WebhookWorkspaceActivityListOptions): Promise<Page<WebhookActivityResource>>
```

Returns one page of the whole workspace's webhook audit log, newest first, the Activity tab of Settings, Webhooks. Every change is a row: `created`, `updated`, `enabled`, `disabled`, `auto_disabled`, `secret_rotated`, `tested`, `replayed` and `removed`, whether it came from the app, from a key over the API, or from OpenEmail itself. `actor` says who, with `label` already formatted the way the app shows it: `@username` for a person, `API key <name>` for a key, and `actor` is null when OpenEmail made the change on its own, such as switching an endpoint off after 100 failed events in a row. `detail` carries what moved: the URL, `previousUrl` when it changed, the event types and allowlists an update set, or the status and response code a test or a replay got.

`endpointIds` narrows it to some endpoints, removed ones included, and `since` and `until` keep a window.

Scopes: `webhooks:read`.

**Parameters**

- `options.endpointIds` (`Array<string>`): Endpoint ids to read, at most 50, sent comma-separated. Left out, every endpoint in the workspace.
- `options.since` (`Date | string`): Only rows at or after this instant. A `Date` is sent as ISO 8601, and a string must already be one.
- `options.until` (`Date | string`): Only rows before this instant. It has to be later than `since`, or the server answers 400 `invalid_parameter`.
- `options.limit` (`number`): Rows per page, a whole number from 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): The `nextCursor` from the previous page, passed back unchanged. Never build one yourself.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`Page<WebhookActivityResource>` with `items`, `hasMore` and `nextCursor`. Each item has `id`, `endpointId`, `endpointLabel`, `type`, `createdAt`, `actor` and `detail`.

**Example**

```ts
const page = await openemail.webhooks.listWorkspaceActivity({ since: '2026-09-01T00:00:00Z' })

for (const change of page.items) {
    console.log(change.endpointLabel, change.type, change.actor?.label ?? 'OpenEmail')
}
```

**Notes**

- The cursor is opaque: pass `nextCursor` back as it came. One this list did not hand out is a 400 `invalid_cursor`.

Also available in: API [`GET /webhooks/activity`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-activity); CLI [`openemail webhooks list-workspace-activity`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-list-workspace-activity).

### `webhooks.listAllWorkspaceActivity()`

Collect the whole webhook audit log into one array

```ts
listAllWorkspaceActivity(options?: WebhookWorkspaceActivityListOptions): Promise<Array<WebhookActivityResource>>
```

Walks every page of `listWorkspaceActivity` under the same filters and resolves with every change, newest first.

Scopes: `webhooks:read`.

**Parameters**

- `options.endpointIds` (`Array<string>`): Endpoint ids to read, at most 50, sent comma-separated. Left out, every endpoint in the workspace.
- `options.since` (`Date | string`): Only rows at or after this instant. A `Date` is sent as ISO 8601, and a string must already be one.
- `options.until` (`Date | string`): Only rows before this instant. It has to be later than `since`, or the server answers 400 `invalid_parameter`.
- `options.limit` (`number`): Page size for each request, 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): Starts the walk from this cursor instead of the newest row.
- `options.signal` (`AbortSignal`): Cancels the request in flight and the walk with it.
- `options.apiKey` (`string`): Overrides the client API key for every page of this walk.

**Returns**

`Array<WebhookActivityResource>`, newest first.

**Example**

```ts
const changes = await openemail.webhooks.listAllWorkspaceActivity({ since: new Date('2026-09-01T00:00:00Z') })

console.log(changes.filter((change) => change.actor?.kind === 'apiKey').length, 'changes made by keys')
```

**Notes**

- If any page fails the promise rejects and the rows already fetched are discarded.

Also available in: API [`GET /webhooks/activity`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-activity).

### `webhooks.iterateWorkspaceActivity()`

Stream the whole webhook audit log one change at a time

```ts
iterateWorkspaceActivity(options?: WebhookWorkspaceActivityListOptions): AsyncGenerator<WebhookActivityResource, void, undefined>
```

An async generator over `listWorkspaceActivity` under the same filters, fetching a page only when the one before is drained.

Scopes: `webhooks:read`.

**Parameters**

- `options.endpointIds` (`Array<string>`): Endpoint ids to read, at most 50, sent comma-separated. Left out, every endpoint in the workspace.
- `options.since` (`Date | string`): Only rows at or after this instant. A `Date` is sent as ISO 8601, and a string must already be one.
- `options.until` (`Date | string`): Only rows before this instant. It has to be later than `since`, or the server answers 400 `invalid_parameter`.
- `options.limit` (`number`): Page size per request, 1 to 100. The server defaults to 25.
- `options.cursor` (`string`): Starts the walk from this cursor instead of the newest row.
- `options.signal` (`AbortSignal`): Cancels the request in flight and ends the iteration.
- `options.apiKey` (`string`): Overrides the client API key for every page of this walk.

**Returns**

`AsyncGenerator<WebhookActivityResource, void, undefined>` yielding one change per step.

**Example**

```ts
for await (const change of openemail.webhooks.iterateWorkspaceActivity()) {
    if (change.type === 'removed') console.log(change.endpointLabel, 'was removed by', change.actor?.label)
}
```

Also available in: API [`GET /webhooks/activity`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-activity).

### `webhooks.listEvents()`

List the events an endpoint can subscribe to

```ts
listEvents(options?: RequestScope): Promise<WebhookCatalogueResource>
```

Returns every event an endpoint can name in `eventTypes`, each with a sentence saying when it fires, and the limits an endpoint is held to: how many endpoints the workspace may have, which its plan decides, and how many addresses and domains one allowlist may name.

An endpoint that names no events receives every email event except `email.replied`, so `email.replied` and the domain, suppression, file and form families only reach an endpoint that asks for them by name.

Scopes: `webhooks:read`.

**Parameters**

- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`WebhookCatalogueResource` with `events`, `maxEndpoints`, `maxAddresses` and `maxDomains`.

**Example**

```ts
const catalogue = await openemail.webhooks.listEvents()

for (const event of catalogue.events) console.log(event.id, event.label)
console.log(`up to ${catalogue.maxEndpoints} endpoints`)
```

**Notes**

- The same events are exported as `WEBHOOK_EVENTS`, so a build that only needs the ids can skip the call.
- Retried automatically on network failure, since it only reads.

Also available in: API [`GET /webhooks/events`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-events); CLI [`openemail webhooks list-events`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-list-events).

### `webhooks.stats()`

Read how webhook deliveries went inside a window

```ts
stats(options?: WebhookStatsOptions): Promise<WebhookStatsResource>
```

Returns the numbers behind the Analytics tab of the Webhooks page: how many delivery attempts were made, how many were delivered and how many failed, the median time a receiver took to answer, a series of buckets, the events sent and the response codes received.

It covers every endpoint, or the ones `endpointIds` names. Each try of an event counts as one attempt, so an event retried three times counts three times. The window runs from `since` to `until`, and left out it is the 30 days before now. `grain` sets the bucket width and the key shape, `YYYY-MM-DD`, `YYYY-MM-DDTHH` or `YYYY-MM-DDTHH:MM`, and `offsetMinutes` shifts the boundaries so days break where the reader's day does.

Scopes: `webhooks:read`.

**Parameters**

- `options.endpointIds` (`Array<string>`): Only these endpoints, at most 50. Left out, every endpoint.
- `options.since` (`Date | string`): The start of the window, a `Date` or an ISO 8601 instant. Defaults to 30 days before `until`.
- `options.until` (`Date | string`): The end of the window, not included. Defaults to now.
- `options.grain` (`TrackingGrain`): Bucket width: `minute`, `hour` or `day`, defaulting to `day`.
- `options.offsetMinutes` (`number`): Minutes east of UTC to bucket in, from -840 to 840, defaulting to 0. Pass `-new Date().getTimezoneOffset()` for the local zone.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client API key for this call only.

**Returns**

`WebhookStatsResource` with the window it covered, `totals`, `buckets`, `events` and `codes`.

**Example**

```ts
const stats = await openemail.webhooks.stats({ since: new Date(Date.now() - 7 * 86_400_000), grain: 'day' })

console.log(`${stats.totals.failed} of ${stats.totals.attempts} attempts failed`)
console.log(stats.codes)
```

**Notes**

- `buckets` is sparse: a bucket with no attempt has no entry, so a chart must fill the gaps.
- `medianDurationMs` is null when nothing was sent in the window.
- Retried automatically on network failure, since it only reads.

Also available in: API [`GET /webhooks/stats`](https://openemail.uk/docs/api/reference/webhooks#get-webhooks-stats); CLI [`openemail webhooks stats`](https://openemail.uk/docs/cli/reference/webhooks#webhooks-stats).
