openemail.webhooks
Bu ad alanındaki her yöntem: imzası, parametreleri, döndürdüğü değer ve bir örnek.
Yöntemler
Endpoints that receive signed mailbox events, their secrets and their delivery log.
webhooks.list()webhooks.listAll()webhooks.iterate()webhooks.get()webhooks.create()webhooks.update()webhooks.delete()webhooks.rotateSecret()webhooks.test()webhooks.listDeliveries()webhooks.listAllDeliveries()webhooks.iterateDeliveries()webhooks.getDelivery()webhooks.replayDelivery()webhooks.listWorkspaceDeliveries()webhooks.listAllWorkspaceDeliveries()webhooks.iterateWorkspaceDeliveries()webhooks.listActivity()webhooks.listAllActivity()webhooks.iterateActivity()webhooks.listWorkspaceActivity()webhooks.listAllWorkspaceActivity()webhooks.iterateWorkspaceActivity()webhooks.listEvents()webhooks.stats()
webhooks.list()
List the webhook endpoints in the workspace
list(options?: ListOptions): Promise<Page<WebhookResource>>Resolves one page of the webhook endpoints registered on the key's workspace, newest first. listAll collects every page and iterate walks them lazily.
Signing secrets are never part of a read. Only create and rotateSecret return secret, so a lost secret cannot be recovered from here. An endpoint subscribed to every event, which is what an endpoint created without eventTypes is, reports eventTypes as ['*'] rather than an empty array.
Read enabled, disabledReason and consecutiveFailures as the health summary. An endpoint the server switched off after 100 consecutive failed deliveries shows enabled: false with disabledAt and a reason, while one you disabled yourself through update has both of those null.
Parametreler
options.limitnumberPage size, from 1 to 100. The server defaults to 25.
options.cursorstringThe
nextCursorof the previous page. Leave it out for the first page.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
Page<WebhookResource> with items, hasMore and nextCursor. Each item has id, url, description, eventTypes, enabled, disabledAt, disabledReason, consecutiveFailures, addressAllowlist, domainAllowlist, lastDeliveryAt and createdAt.
Örnek
const hooks = await openemail.webhooks.listAll() const unhealthy = hooks.filter((hook) => !hook.enabled || hook.consecutiveFailures > 0) console.log(unhealthy.map((hook) => [hook.url, hook.disabledReason]))Notlar
A narrowed key reads every endpoint, and may write one whose own
addressAllowlistanddomainAllowlistsit inside what the key holds. A write that would take an endpoint wider than the key is 422capability_unsupportedonaddressAllowlist.lastDeliveryAtmoves on failed attempts as well as successful ones, so it shows the endpoint is being called, not that it is healthy.The cursor is opaque and holds where the last row sat in this order, so a row deleted or edited between pages never breaks the walk: the next page starts at the first row that sorts after it. A cursor this list did not hand out is a 400
invalid_cursor.
Şurada da var
webhooks.listAll()
Collect every webhook endpoint into one array
listAll(options?: ListOptions): Promise<Array<WebhookResource>>Walks every page of list and resolves with all webhook endpoints, newest first. One request per page.
Parametreler
options.limitnumberPage size for each request, from 1 to 100. The server defaults to 25.
options.cursorstringStarts the walk after this cursor instead of the first page.
options.signalAbortSignalCancels the request in flight and the walk with it.
options.apiKeystringOverrides the client API key for every page of this walk.
Döndürür
Array<WebhookResource> holding every webhook endpoint.
Örnek
const all = await openemail.webhooks.listAll({ limit: 100 }) console.log(all.length)Notlar
If any page fails the promise rejects and the webhook endpoints already fetched are discarded.
Şurada da var
webhooks.iterate()
Stream the webhook endpoints one at a time
iterate(options?: ListOptions): AsyncGenerator<WebhookResource, void, undefined>Returns an async generator that yields webhook endpoints individually, newest first, and requests the next page only once the current one is drained. Nothing is fetched until you consume it, and breaking out of the loop stops the requests.
Parametreler
options.limitnumberPage size for each request, from 1 to 100. The server defaults to 25.
options.cursorstringStarts the walk after this cursor instead of the first page.
options.signalAbortSignalCancels the request in flight and the walk with it.
options.apiKeystringOverrides the client API key for every page of this walk.
Döndürür
AsyncGenerator<WebhookResource, void, undefined> yielding one webhook endpoint per step.
Örnek
for await (const item of openemail.webhooks.iterate()) { console.log(item)}Notlar
The generator is lazy, so an abandoned loop costs only the pages you consumed.
Şurada da var
webhooks.get()
Read one webhook endpoint by id
get(id: string, options?: RequestScope): Promise<WebhookResource>Resolves a single endpoint with its URL, subscription list, enabled state and delivery health. The signing secret is never part of a read. It appears only in the responses of create and rotateSecret, and a lost one is replaced with rotateSecret rather than read back.
An id from another workspace answers exactly like one that never existed, with 404 resource_not_found, so a 404 does not tell you whether the endpoint was deleted or was never yours.
consecutiveFailures resets to 0 on any successful delivery and when update sets enabled to true. When it reaches 100 the server disables the endpoint, fills in disabledAt and disabledReason, and emails the workspace owner and every member whose role can read webhooks.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
WebhookResource with id, url, description, eventTypes, enabled, disabledAt, disabledReason, consecutiveFailures, addressAllowlist, domainAllowlist, lastDeliveryAt and createdAt. No secret.
Örnek
const hook = await openemail.webhooks.get('whe_3f9c2a7b1e4d8f60a5c7b92d') if (!hook.enabled && hook.disabledReason) { console.log(hook.disabledAt, hook.disabledReason)}Notlar
eventTypesof['*']means the endpoint named none, so it receives the defaultemail.*set.email.replied,domain.*,suppression.*,file.*andform.*sit outside that set and have to be named explicitly.A GET is retried automatically on network failure and on 408, 429 and 5xx responses, up to the client
maxRetries.
Şurada da var
webhooks.create()
Register an HTTPS endpoint for mailbox events
create(body: WebhookCreate, options?: RequestScope): Promise<CreatedWebhookResource>Registers a receiver URL and subscribes it to events on the key's workspace. The endpoint starts enabled, so the next matching event is delivered to it straight away. Leave eventTypes out, or pass an empty array, and the endpoint receives the default set, which is the email.* events other than email.replied. Every family outside it has to be named: email.replied, domain.*, suppression.*, file.* and form.*. Reads report an unnamed subscription as ['*'].
By default an endpoint hears about every address the workspace owns. addressAllowlist and domainAllowlist narrow it, exactly as the same two lists narrow an API key: name whole domains, single addresses, or both. An event reaches the endpoint when the address or domain it concerns is covered. Events that name no address at all, such as suppression.removed, reach every endpoint whatever its lists say. form.* is the exception: a sign-up belongs to the whole workspace, so an endpoint limited to some addresses or domains never receives form.submitted or form.confirmed.
This response is the only place the full secret ever appears. Every later read omits it, so store it before doing anything else, and if it is lost call rotateSecret. The secret is whsec_ followed by 43 base64url characters, and the HMAC key is the whole string including the prefix, so pass it to verifyWebhookSignature exactly as returned.
url must be https. localhost, hosts ending .localhost, .internal or .local, and IP literals in loopback, private, link local, carrier grade NAT, multicast or unique local ranges are refused with 422 invalid_webhook_url. The host is resolved again on every delivery, and an attempt to a name that resolves into one of those ranges is recorded as failed without being sent. Deliveries never follow redirects, so register the final address.
Parametreler
body.urlstringZorunluThe https receiver URL. Another scheme or a blocked host is 422
invalid_webhook_url. Stored in normalised form, so theurlread back can differ cosmetically.body.eventTypesArray<WebhookEvent>Events to subscribe to. Omit it, or send
[], for the defaultemail.*set:email.received,email.sent,email.failed,email.cancelled,email.scheduled,email.queued,email.delivered,email.delivery_delayed,email.bounced,email.complained,email.suppressed,email.opened,email.clickedandemail.downloaded.email.replied,domain.verified,domain.sending_changed,domain.deleted,suppression.added,suppression.removed,file.uploaded,file.deleted,form.submittedandform.confirmedare outside that set and have to be named.body.descriptionstringFree text note, at most 200 characters.
body.addressAllowlistArray<string>Single addresses this endpoint hears about. An event is delivered when the address it concerns is on this list, or when its domain is in
domainAllowlist. Leave both empty and the endpoint hears about every address the workspace owns. At most 50, and an address this workspace does not own is 422invalid_parameter.body.domainAllowlistArray<string>Whole domains this endpoint hears about, including addresses added to them later. A domain also carries its own
domain.*events. At most 25. An address whose domain is already listed here is dropped fromaddressAllowlistwhen the endpoint is saved, so the two lists never overlap.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
CreatedWebhookResource, a WebhookResource plus the plaintext secret. Alongside it you get id, url, description, eventTypes, enabled, disabledAt, disabledReason, consecutiveFailures, addressAllowlist, domainAllowlist, lastDeliveryAt and createdAt.
Örnek
const hook = await openemail.webhooks.create({ url: 'https://hooks.acme.com/openemail', eventTypes: ['email.received', 'email.bounced', 'email.complained'], description: 'Support desk sync'}) console.log(hook.secret)console.log(hook.id, hook.eventTypes)Notlar
Verify each delivery with
verifyWebhookSignature({ payload, headers, secret })from the package root, passing the raw request body. It checks theX-OpenEmail-SignatureHMAC-SHA256 over the timestamp, a dot and the raw body in constant time, rejects a timestamp more than 300 seconds off, throws on failure and returns{ id, type, createdAt, data }.Each attempt is one POST with a 5 second timeout. A failure worth repeating (no answer, 408, 425, 429 or a 5xx) is tried again after 1 minute, 5 minutes, 30 minutes, 2 hours, 5 hours, 10 hours and 10 hours, up to 8 attempts over about 27 and a half hours, each wait varied by up to 10% and stretched when your server's
Retry-Afterasks for longer, up to 6 hours. A 410 Gone switches the endpoint off.listDeliveriesshows every attempt with its number, andreplayDeliverysends one of them again, one event at a time, once your receiver is fixed.A workspace holds 10 endpoints by default, and support can raise that for a workspace that needs more. The next one past the limit is 422
workspace_limit_reached. A narrowed key may create an endpoint, but only one whose own lists sit inside what the key holds; anything wider is 422capability_unsupportedonaddressAllowlist.Not retried automatically, so a network failure can leave an endpoint created with a secret you never saw. Check
listbefore creating it again.
Şurada da var
webhooks.update()
Change an endpoint URL, events or enabled state
update(id: string, patch: WebhookPatch, options?: RequestScope): Promise<WebhookResource>Patches the URL, subscription list, description or enabled flag of one endpoint. Every field is optional, and an empty patch is accepted and changes nothing you can read back. A new url goes through the same https and host checks as create, and description: null clears the note.
eventTypes replaces the subscription set wholesale, so send the complete list you want rather than a delta. An empty array does not unsubscribe: it puts the endpoint back on the default email.* set. To stop deliveries, set enabled to false instead.
addressAllowlist and domainAllowlist replace the endpoint's scope the same way, wholesale rather than as a delta. Send both empty to widen it back to every address the workspace owns. Each list is checked against the domains and addresses this workspace actually owns, and an unknown one is 422 invalid_parameter.
Writing enabled clears disabledAt and disabledReason either way, so an endpoint you switch off yourself reports both as null. Setting it back to true also resets consecutiveFailures to 0, which is how an endpoint the server disabled after 100 failures is brought back. Events that fire while an endpoint is disabled are never delivered to it later, but a delivery that failed before it was switched off can be sent again with replayDelivery once it is back on, one event at a time.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.patch.urlstringReplacement https URL, checked against the same host rules as
create.patch.eventTypesArray<WebhookEvent>Complete replacement subscription set.
[]means the defaultemail.*set.patch.addressAllowlistArray<string>Complete replacement list of single addresses this endpoint hears about. At most 50. Send
[]on both lists to hear about every address again.patch.domainAllowlistArray<string>Complete replacement list of whole domains this endpoint hears about, including addresses added to them later. At most 25.
patch.descriptionstring | nullReplacement note of at most 200 characters, or null to clear it.
patch.enabledbooleanFalse stops deliveries. True resumes them and resets
consecutiveFailures.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
WebhookResource as saved. The signing secret is untouched and not included.
Örnek
const updated = await openemail.webhooks.update('whe_3f9c2a7b1e4d8f60a5c7b92d', { eventTypes: ['email.sent', 'email.bounced', 'email.complained'], enabled: true}) console.log(updated.eventTypes, updated.consecutiveFailures)Notlar
Read the current
eventTypesfirst if you mean to add one, since a partial list silently unsubscribes the rest. The same applies to the two allowlists. Do not send back['*']as read: it is a 422invalid_parameter, and[]is how to ask for the default set.This route never touches the signing secret. Use
rotateSecretfor that.Retried automatically on network failure and retryable statuses, since the same patch applied twice lands on the same row.
Şurada da var
webhooks.delete()
Delete an endpoint and its delivery log
delete(id: string, options?: RequestScope): Promise<DeletedWebhookResource>Removes the endpoint for good. Deliveries stop immediately, the signing secret is gone, and the delivery log for the endpoint is deleted with it, so read it with listAllDeliveries first if you need it for an audit trail.
There is no undo and no soft delete. If the aim is only to pause deliveries, call update with enabled: false and keep the endpoint, its secret and its log.
The response is a tombstone rather than an empty body, so a log line can name what went. Deleting frees a slot against the workspace's endpoint limit straight away.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
DeletedWebhookResource with object set to webhook, the id and deleted: true.
Örnek
const log = await openemail.webhooks.listAllDeliveries('whe_3f9c2a7b1e4d8f60a5c7b92d') const removed = await openemail.webhooks.delete('whe_3f9c2a7b1e4d8f60a5c7b92d') console.log(log.length, removed.deleted)Notlar
Not idempotent: a second call on the same id is 404
resource_not_found, and the SDK does not retry it after a network failure.A narrowed key may delete only an endpoint whose own allowlists sit inside what the key holds; any other is 422
capability_unsupportedonaddressAllowlist.
Şurada da var
webhooks.rotateSecret()
Issue a new signing secret for an endpoint
rotateSecret(id: string, options?: RequestScope): Promise<CreatedWebhookResource>Generates a new signing secret and resolves with the endpoint plus the new plaintext secret. As with create, this response is the only place that secret appears, so store it before anything else.
There is no overlap window. Every delivery is signed at send time with the current secret, so the old one stops verifying the moment this call commits, and any event that fires before your receiver has the new secret fails verification on your side.
The safe order is to deploy a receiver that tries both the old secret and a new one read from config, call this, write the returned secret to config, then drop the old one. test confirms the new secret verifies before you remove the fallback.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
CreatedWebhookResource: the full WebhookResource plus the new secret, formatted whsec_ followed by 43 base64url characters.
Örnek
const rotated = await openemail.webhooks.rotateSecret('whe_3f9c2a7b1e4d8f60a5c7b92d') console.log(rotated.secret) const check = await openemail.webhooks.test(rotated.id) console.log(check.delivery?.status)Notlar
There is no request body and the success status is 200, not 201.
Not retried automatically. A lost response means a secret you never saw is already live, so rotate again rather than waiting.
Subscriptions, enabled state and
consecutiveFailuresare left as they were.
Şurada da var
webhooks.test()
Send a synthetic event and report how delivery went
test(id: string, options?: RequestScope): Promise<WebhookTestResource>Posts a signed synthetic email.sent event to the endpoint and waits for the attempt to finish before resolving. The payload data is { test: true, note } and no mail is sent, so it is safe against a production receiver. It proves the URL is reachable and that your signature check accepts the current secret before real mail depends on it.
The outcome comes back as delivery, read from the newest row of the delivery log. status is delivered for any 2xx answer and failed otherwise, responseCode is the HTTP status or null when no response arrived, such as a DNS failure or the 5 second timeout, and error explains a failure. A 3xx counts as failed because redirects are never followed.
The event goes out whatever the endpoint subscribes to, and even when it is disabled. It is recorded like any delivery, so it appears in listDeliveries and can be sent again with replayDelivery, but it is tried once and leaves consecutiveFailures and lastDeliveryAt alone, so a failing test never counts toward the 100 that disable an endpoint. A 410 Gone answer does switch the endpoint off, as it would for a real event.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
WebhookTestResource with object set to webhook_test, the endpoint id, and delivery holding status, responseCode, durationMs and error, or null when no delivery row could be read back.
Örnek
const result = await openemail.webhooks.test('whe_3f9c2a7b1e4d8f60a5c7b92d') if (result.delivery?.status !== 'delivered') { console.log(result.delivery?.responseCode, result.delivery?.error)}Notlar
The call resolves with 200 when your receiver fails. Branch on
delivery.status, not on whether the promise rejected.A 4xx from your receiver is a useful answer: the URL is reachable and the rejection came from your own handler, often its signature check.
Not retried automatically, since every call sends another request to your receiver.
If a real event reaches the same endpoint at the same moment,
deliverycan describe that attempt instead, because it reads the newest log row.
Şurada da var
webhooks.listDeliveries()
List one page of delivery attempts for one endpoint
listDeliveries(id: string, options?: WebhookDeliveryListOptions): Promise<Page<WebhookDeliveryResource>>Returns one page of an endpoint's delivery log, newest first. Nothing is dropped from the log, so following nextCursor while hasMore is true reaches the endpoint's very first delivery, and listAllDeliveries and iterateDeliveries do that walk for you. status, since and until narrow it the way the Deliveries tab of the app does: status: 'failed' is its "only failed" switch.
Each attempt is one POST with a 5 second timeout, and one event can appear several times: when the failure is worth repeating, a delivery is tried up to 8 times, as it happens and then after 1 minute, 5 minutes, 30 minutes, 2 hours, 5 hours, 10 hours and 10 hours, about 27 and a half hours in all, and each replayDelivery adds a row of its own. attempt and maxAttempts say which try a row is, and eventId is the same across all of them, so this log distinguishes a retry from a new event. nextAttemptAt is when the automatic retry that follows a row is due, and null when none is waiting, so a failed row with a time in it is not the final word. status is delivered for a 2xx answer and failed for anything else, including a 3xx, since redirects are not followed.
responseCode null means no response arrived, such as a DNS or TLS failure or the timeout, which is a different fact from a receiver that answered. durationMs is null only when the attempt was never made because the server could not read the signing secret, and error then says so. The body that was sent and your server's answer are not part of this response, and getDelivery returns both. listWorkspaceDeliveries reads every endpoint at once.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.options.status'delivered' | 'failed'failedkeeps only the attempts that did not get a 2xx, the "only failed" view of the app;deliveredkeeps the rest.options.sinceDate | stringOnly rows at or after this instant. A
Dateis sent as ISO 8601, and a string must already be one.options.untilDate | stringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitnumberRows per page, a whole number from 1 to 100. The server defaults to 25.
options.cursorstringThe
nextCursorfrom the previous page, passed back unchanged. Never build one yourself.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
Page<WebhookDeliveryResource> with items, hasMore and nextCursor. Each item has id, endpointId, eventType, eventId, status, responseCode, durationMs, attempt, maxAttempts, error, createdAt and nextAttemptAt.
Örnek
const page = await openemail.webhooks.listDeliveries('whe_3f9c2a7b1e4d8f60a5c7b92d', { status: 'failed', since: new Date(Date.now() - 24 * 60 * 60 * 1000), limit: 50}) console.log(page.items.map((delivery) => [delivery.eventType, delivery.responseCode, delivery.error]))console.log(page.hasMore, page.nextCursor)Notlar
Synthetic events from
testappear here too, recorded asemail.sent.Each endpoint's copy of an event gets its own
evt_id, sent in theX-OpenEmail-Deliveryheader and as the payloadid, and every retry and replay of that copy keeps it. One event fanned out to two endpoints arrives with two different ids, and a repeat to one endpoint arrives with the same one.The cursor stays valid under every filter as long as each page sends the same
status,sinceanduntil, whichlistAll…anditerate…do for you.A 404
resource_not_foundmeans the endpoint id is wrong or belongs to another workspace, not that the log is empty. A cursor that names no delivery of this endpoint is a 400invalid_cursor, and asinceoruntilthat does not parse is a 400invalid_parameter.
Şurada da var
webhooks.listAllDeliveries()
Collect an endpoint's whole delivery log into one array
listAllDeliveries(id: string, options?: WebhookDeliveryListOptions): Promise<Array<WebhookDeliveryResource>>Walks every page of an endpoint's delivery log and resolves with all of its attempts, newest first, under the same status, since and until filters as listDeliveries. The log is never pruned, so an endpoint that has been busy for a long time can hold a great many rows; narrow it with a window, or prefer iterateDeliveries when you can stop early.
Pages are keyset on createdAt and id, walking backwards in time. Attempts recorded after the walk starts are newer than its first page and are not included.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.options.status'delivered' | 'failed'failedkeeps only the attempts that did not get a 2xx, the "only failed" view of the app;deliveredkeeps the rest.options.sinceDate | stringOnly rows at or after this instant. A
Dateis sent as ISO 8601, and a string must already be one.options.untilDate | stringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitnumberPage size for each request, 1 to 100. The server defaults to 25.
options.cursorstringStarts the walk from this cursor instead of the newest row.
options.signalAbortSignalCancels the request in flight and the walk with it.
options.apiKeystringOverrides the client API key for every page of this walk.
Döndürür
Array<WebhookDeliveryResource> holding every matching attempt on the endpoint, newest first.
Örnek
const failures = await openemail.webhooks.listAllDeliveries('whe_3f9c2a7b1e4d8f60a5c7b92d', { status: 'failed', limit: 100 }) const failedEvents = new Set(failures.map((delivery) => delivery.eventId)) console.log(`${failedEvents.size} events had a failed attempt`)Notlar
If any page fails the promise rejects and the attempts already fetched are discarded.
One request per page, so a large log takes many requests. Read it with
iterateDeliveriesto stop as soon as you have what you need.
Şurada da var
webhooks.iterateDeliveries()
Stream an endpoint's delivery attempts one at a time, newest first
iterateDeliveries(id: string, options?: WebhookDeliveryListOptions): AsyncGenerator<WebhookDeliveryResource, void, undefined>Returns an async generator over an endpoint's delivery log that yields attempts individually and fetches the next page only when the current one is drained, under the same status, since and until filters as listDeliveries. Nothing is requested until you consume it, and breaking out of the loop stops further requests, which makes it the right way to find the latest attempt of some kind without reading the whole history.
The walk ends when hasMore is false, when a page comes back empty, or when the server repeats a cursor. Attempts recorded after the walk starts are newer than its cursor and are not yielded.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.options.status'delivered' | 'failed'failedkeeps only the attempts that did not get a 2xx, the "only failed" view of the app;deliveredkeeps the rest.options.sinceDate | stringOnly rows at or after this instant. A
Dateis sent as ISO 8601, and a string must already be one.options.untilDate | stringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitnumberPage size per request, 1 to 100. The server defaults to 25.
options.cursorstringStarts the walk from this cursor instead of the newest row.
options.signalAbortSignalCancels the request in flight and ends the iteration.
options.apiKeystringOverrides the client API key for every page of this walk.
Döndürür
AsyncGenerator<WebhookDeliveryResource, void, undefined> yielding one attempt per step.
Örnek
for await (const delivery of openemail.webhooks.iterateDeliveries('whe_3f9c2a7b1e4d8f60a5c7b92d', { status: 'failed' })) { if (delivery.nextAttemptAt === null) { console.log(delivery.createdAt, delivery.eventType, delivery.responseCode, delivery.error) break }}Notlar
An aborted
options.signalrejects the pending page request, which throws out of thefor awaitloop.
Şurada da var
webhooks.getDelivery()
Read one delivery attempt in full, with the body that was sent
getDelivery(id: string, deliveryId: string, options?: RequestScope): Promise<WebhookDeliveryDetailResource>Resolves one attempt from an endpoint's delivery log with what listDeliveries leaves out. payload is the exact JSON body that was POSTed, { id, type, createdAt, data }, and responseBody is the first 2,000 characters your server answered, or null when nothing came back or the answer was a redirect.
attempts lists every try of the same event on this endpoint, oldest first: the first attempt, the automatic retries and any replays, each with its own id, attempt, status, responseCode, error and createdAt. They share eventId, which is the payload id your receiver saw. nextAttemptAt is when the next automatic retry of the event is due, whichever attempt it follows, and null when none is waiting.
replayRefusal says whether replayDelivery would accept this attempt before you call it: null when it would, and otherwise the code and message the replay would be refused with, such as webhook_disabled while the endpoint is switched off, or retry_in_progress while an automatic retry of the same event is being sent.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.deliveryIdstringZorunluDelivery id,
whd_followed by 24 hex characters, aslistDeliveriesreturns it.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
WebhookDeliveryDetailResource: the WebhookDeliveryResource fields (id, eventType, eventId, status, responseCode, durationMs, attempt, maxAttempts, error, createdAt, nextAttemptAt) plus endpointId, payload, responseBody, attempts and replayRefusal.
Örnek
const detail = await openemail.webhooks.getDelivery('whe_3f9c2a7b1e4d8f60a5c7b92d', 'whd_8c1e4a7f2b9d3e6a0c5f1b28') console.log(detail.payload?.type, detail.responseCode, detail.responseBody)console.log(detail.attempts.map((attempt) => [attempt.attempt, attempt.status, attempt.responseCode])) if (detail.replayRefusal) console.log(detail.replayRefusal.code, detail.replayRefusal.message)Notlar
A delivery id that belongs to another endpoint, even one in the same workspace, is 404
resource_not_found, exactly like one that never existed.Your server's answer is cut at 2,000 characters when it is recorded, so a longer one reads back truncated.
A GET is retried automatically on network failure and on 408, 429 and 5xx responses, up to the client
maxRetries.A narrowed key may read a delivery only on an endpoint whose own allowlists sit inside what the key holds, where holding one address never covers its whole domain, because the body names the addresses the event is about; any other is 422
capability_unsupportedonaddressAllowlist. Over OAuth only the workspace owner, or a member whose role holdsaddresses:all, may read one, and any other member's token is 403owner_only. That member's token is held to the domains the workspace has now, so it reads only a delivery of an endpoint with allowlists, and one with none is 422capability_unsupportedfor it too.
Şurada da var
webhooks.replayDelivery()
Send one stored event to the endpoint again, now
replayDelivery(id: string, deliveryId: string, options?: RequestScope): Promise<WebhookReplayResource>Posts the event behind a recorded attempt to the endpoint once more, straight away, and resolves when that attempt has finished. The body is the one stored with the original, with the same id, type, createdAt and data, so a receiver that drops ids it has already handled treats the replay as the event it already knows. Only X-OpenEmail-Signature is new, because every POST is signed with the current secret at the moment it goes out, so a replay verifies after a rotateSecret too.
It accepts a delivered attempt as well as a failed one. Replaying a success is how a receiver that lost its copy, or handled it wrongly, is brought back in step. Any attempt of the event will do, since they all carry the same event.
The replay is recorded in the log as a new delivery, attempt 1 of 1, and is never retried automatically. Before it goes out, the automatic retries of the same event that have not started are paused, so the receiver never gets two copies at once. When the replay is delivered they stay cancelled; when it fails they resume on their schedule. If an automatic retry of the event is being sent at that very moment, the replay sends nothing and is refused with 409 retry_in_progress, and if another replay of the same event is still being sent, it is refused with 409 replay_in_progress, so two copies never go out at once. The call resolves with 200 whatever your server answered, so branch on delivery.status rather than on whether the promise rejected.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.deliveryIdstringZorunluAny attempt of the event to send again,
whd_followed by 24 hex characters.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
WebhookReplayResource with object set to webhook_replay, id (the new delivery), endpointId, replayOf (the attempt you named), eventId, eventType, and delivery holding status, responseCode, durationMs and error.
Örnek
const replay = await openemail.webhooks.replayDelivery('whe_3f9c2a7b1e4d8f60a5c7b92d', 'whd_8c1e4a7f2b9d3e6a0c5f1b28') if (replay.delivery.status !== 'delivered') { console.log(replay.delivery.responseCode, replay.delivery.error)}Notlar
Refused with 409 when nobody who wants the event would receive it:
webhook_disabledwhile the endpoint is switched off,event_not_subscribedwhen it no longer listens for the event type,event_out_of_scopewhen its allowlists no longer cover the address the event is about,delivery_not_replayablewhen the attempt has no stored event,retry_in_progresswhile an automatic retry of the same event is being sent, andreplay_in_progresswhile another replay of it is. Wait a few seconds and checkgetDeliverybefore replaying again, since that retry or replay may deliver it.getDeliveryreports the same answer in advance asreplayRefusal. A synthetic event fromtestreplays whatever the endpoint subscribes to.Not retried automatically, because a retry after a lost response would send the event again. A receiver that drops repeated ids handles that safely, but the SDK does not assume yours does.
A delivered replay resets
consecutiveFailures, and a failed one does not add to it. A 410 Gone switches the endpoint off, as it does for an automatic delivery.A narrowed key may replay only on an endpoint whose own allowlists sit inside what the key holds; any other is 422
capability_unsupportedonaddressAllowlist.
Şurada da var
webhooks.listWorkspaceDeliveries()
List one page of delivery attempts across every endpoint
listWorkspaceDeliveries(options?: WebhookWorkspaceDeliveryListOptions): Promise<Page<WebhookDeliveryResource>>Returns one page of the whole workspace's delivery log, newest first: the all-endpoints Deliveries tab of the app. Each row carries endpointId, so the endpoint an attempt went to is never lost. endpointIds narrows it to some endpoints, and status, since and until work exactly as they do on listDeliveries.
Nothing is pruned, so following nextCursor while hasMore is true reaches the workspace's first delivery; listAllWorkspaceDeliveries and iterateWorkspaceDeliveries do that walk. The body that was sent is not here: read it with getDelivery, passing the row's endpointId and id.
Parametreler
options.endpointIdsArray<string>Endpoint ids to read, at most 50, sent comma-separated. Left out, every endpoint in the workspace.
options.status'delivered' | 'failed'failedkeeps only the attempts that did not get a 2xx, the "only failed" view of the app;deliveredkeeps the rest.options.sinceDate | stringOnly rows at or after this instant. A
Dateis sent as ISO 8601, and a string must already be one.options.untilDate | stringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitnumberRows per page, a whole number from 1 to 100. The server defaults to 25.
options.cursorstringThe
nextCursorfrom the previous page, passed back unchanged. Never build one yourself.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
Page<WebhookDeliveryResource> with items, hasMore and nextCursor. Each item has id, endpointId, eventType, eventId, status, responseCode, durationMs, attempt, maxAttempts, error, createdAt and nextAttemptAt.
Örnek
const page = await openemail.webhooks.listWorkspaceDeliveries({ status: 'failed', limit: 50 }) for (const delivery of page.items) { console.log(delivery.endpointId, delivery.eventType, delivery.responseCode)}Notlar
An endpoint id in
endpointIdsthat belongs to no endpoint here simply matches nothing. A removed endpoint takes its deliveries with it.The cursor stays valid under every filter as long as each page sends the same
endpointIds,status,sinceanduntil, whichlistAll…anditerate…do for you.The list carries no payloads, so a key narrowed to some addresses may read it; opening a delivery with
getDeliveryis where the narrowing applies.
Şurada da var
webhooks.listAllWorkspaceDeliveries()
Collect the workspace's whole delivery log into one array
listAllWorkspaceDeliveries(options?: WebhookWorkspaceDeliveryListOptions): Promise<Array<WebhookDeliveryResource>>Walks every page of listWorkspaceDeliveries under the same filters and resolves with every matching attempt, newest first. The log is never pruned, so give it a since or endpointIds unless you mean to read all of it, or use iterateWorkspaceDeliveries to stop early.
Parametreler
options.endpointIdsArray<string>Endpoint ids to read, at most 50, sent comma-separated. Left out, every endpoint in the workspace.
options.status'delivered' | 'failed'failedkeeps only the attempts that did not get a 2xx, the "only failed" view of the app;deliveredkeeps the rest.options.sinceDate | stringOnly rows at or after this instant. A
Dateis sent as ISO 8601, and a string must already be one.options.untilDate | stringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitnumberPage size for each request, 1 to 100. The server defaults to 25.
options.cursorstringStarts the walk from this cursor instead of the newest row.
options.signalAbortSignalCancels the request in flight and the walk with it.
options.apiKeystringOverrides the client API key for every page of this walk.
Döndürür
Array<WebhookDeliveryResource> holding every matching attempt, newest first.
Örnek
const lastDay = await openemail.webhooks.listAllWorkspaceDeliveries({ status: 'failed', since: new Date(Date.now() - 24 * 60 * 60 * 1000), limit: 100}) console.log(`${lastDay.length} failed attempts in the last day`)Notlar
If any page fails the promise rejects and the attempts already fetched are discarded.
Şurada da var
webhooks.iterateWorkspaceDeliveries()
Stream the workspace's delivery attempts one at a time, newest first
iterateWorkspaceDeliveries(options?: WebhookWorkspaceDeliveryListOptions): AsyncGenerator<WebhookDeliveryResource, void, undefined>An async generator over listWorkspaceDeliveries under the same filters. It fetches a page only when the one before is drained and stops requesting when you break out of the loop.
Parametreler
options.endpointIdsArray<string>Endpoint ids to read, at most 50, sent comma-separated. Left out, every endpoint in the workspace.
options.status'delivered' | 'failed'failedkeeps only the attempts that did not get a 2xx, the "only failed" view of the app;deliveredkeeps the rest.options.sinceDate | stringOnly rows at or after this instant. A
Dateis sent as ISO 8601, and a string must already be one.options.untilDate | stringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitnumberPage size per request, 1 to 100. The server defaults to 25.
options.cursorstringStarts the walk from this cursor instead of the newest row.
options.signalAbortSignalCancels the request in flight and ends the iteration.
options.apiKeystringOverrides the client API key for every page of this walk.
Döndürür
AsyncGenerator<WebhookDeliveryResource, void, undefined> yielding one attempt per step.
Örnek
for await (const delivery of openemail.webhooks.iterateWorkspaceDeliveries({ status: 'failed' })) { const detail = await openemail.webhooks.getDelivery(delivery.endpointId, delivery.id) if (detail.replayRefusal === null) console.log('replayable', delivery.id)}Notlar
An aborted
options.signalrejects the pending page request, which throws out of thefor awaitloop.
Şurada da var
webhooks.listActivity()
List one page of what happened to one endpoint
listActivity(id: string, options?: WebhookActivityListOptions): Promise<Page<WebhookActivityResource>>Returns one page of an endpoint's audit log, newest first, the Activity tab of the endpoint in the app. Every change is a row: created, updated, enabled, disabled, auto_disabled, secret_rotated, tested, replayed and removed, whether it came from the app, from a key over the API, or from OpenEmail itself. actor says who, with label already formatted the way the app shows it: @username for a person, API key <name> for a key, and actor is null when OpenEmail made the change on its own, such as switching an endpoint off after 100 failed events in a row. detail carries what moved: the URL, previousUrl when it changed, the event types and allowlists an update set, or the status and response code a test or a replay got.
Nothing is pruned, and a removed endpoint keeps its history, so this answers for an endpoint that is gone too. since and until keep a window.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.options.sinceDate | stringOnly rows at or after this instant. A
Dateis sent as ISO 8601, and a string must already be one.options.untilDate | stringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitnumberRows per page, a whole number from 1 to 100. The server defaults to 25.
options.cursorstringThe
nextCursorfrom the previous page, passed back unchanged. Never build one yourself.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
Page<WebhookActivityResource> with items, hasMore and nextCursor. Each item has id, endpointId, endpointLabel, type, createdAt, actor and detail.
Örnek
const page = await openemail.webhooks.listActivity('whe_3f9c2a7b1e4d8f60a5c7b92d') for (const change of page.items) { console.log(change.createdAt, change.type, change.actor?.label ?? 'OpenEmail')}Notlar
A 404 means no endpoint and no history with that id exists in this workspace. The cursor is opaque: pass
nextCursorback as it came, and one this list did not hand out is a 400invalid_cursor.
Şurada da var
webhooks.listAllActivity()
Collect one endpoint's whole audit log into one array
listAllActivity(id: string, options?: WebhookActivityListOptions): Promise<Array<WebhookActivityResource>>Walks every page of listActivity under the same window and resolves with every change, newest first.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.options.sinceDate | stringOnly rows at or after this instant. A
Dateis sent as ISO 8601, and a string must already be one.options.untilDate | stringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitnumberPage size for each request, 1 to 100. The server defaults to 25.
options.cursorstringStarts the walk from this cursor instead of the newest row.
options.signalAbortSignalCancels the request in flight and the walk with it.
options.apiKeystringOverrides the client API key for every page of this walk.
Döndürür
Array<WebhookActivityResource>, newest first.
Örnek
const history = await openemail.webhooks.listAllActivity('whe_3f9c2a7b1e4d8f60a5c7b92d') const rotations = history.filter((change) => change.type === 'secret_rotated') console.log(rotations.map((change) => [change.createdAt, change.actor?.label]))Notlar
If any page fails the promise rejects and the rows already fetched are discarded.
Şurada da var
webhooks.iterateActivity()
Stream one endpoint's audit log one change at a time
iterateActivity(id: string, options?: WebhookActivityListOptions): AsyncGenerator<WebhookActivityResource, void, undefined>An async generator over listActivity under the same window, fetching a page only when the one before is drained.
Parametreler
idstringZorunluEndpoint id,
whe_followed by 24 hex characters.options.sinceDate | stringOnly rows at or after this instant. A
Dateis sent as ISO 8601, and a string must already be one.options.untilDate | stringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitnumberPage size per request, 1 to 100. The server defaults to 25.
options.cursorstringStarts the walk from this cursor instead of the newest row.
options.signalAbortSignalCancels the request in flight and ends the iteration.
options.apiKeystringOverrides the client API key for every page of this walk.
Döndürür
AsyncGenerator<WebhookActivityResource, void, undefined> yielding one change per step.
Örnek
for await (const change of openemail.webhooks.iterateActivity('whe_3f9c2a7b1e4d8f60a5c7b92d')) { if (change.type === 'auto_disabled') { console.log('switched off by OpenEmail at', change.createdAt, change.detail) break }}Şurada da var
webhooks.listWorkspaceActivity()
List one page of what happened to every endpoint
listWorkspaceActivity(options?: WebhookWorkspaceActivityListOptions): Promise<Page<WebhookActivityResource>>Returns one page of the whole workspace's webhook audit log, newest first, the Activity tab of Settings, Webhooks. Every change is a row: created, updated, enabled, disabled, auto_disabled, secret_rotated, tested, replayed and removed, whether it came from the app, from a key over the API, or from OpenEmail itself. actor says who, with label already formatted the way the app shows it: @username for a person, API key <name> for a key, and actor is null when OpenEmail made the change on its own, such as switching an endpoint off after 100 failed events in a row. detail carries what moved: the URL, previousUrl when it changed, the event types and allowlists an update set, or the status and response code a test or a replay got.
endpointIds narrows it to some endpoints, removed ones included, and since and until keep a window.
Parametreler
options.endpointIdsArray<string>Endpoint ids to read, at most 50, sent comma-separated. Left out, every endpoint in the workspace.
options.sinceDate | stringOnly rows at or after this instant. A
Dateis sent as ISO 8601, and a string must already be one.options.untilDate | stringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitnumberRows per page, a whole number from 1 to 100. The server defaults to 25.
options.cursorstringThe
nextCursorfrom the previous page, passed back unchanged. Never build one yourself.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
Page<WebhookActivityResource> with items, hasMore and nextCursor. Each item has id, endpointId, endpointLabel, type, createdAt, actor and detail.
Örnek
const page = await openemail.webhooks.listWorkspaceActivity({ since: '2026-09-01T00:00:00Z' }) for (const change of page.items) { console.log(change.endpointLabel, change.type, change.actor?.label ?? 'OpenEmail')}Notlar
The cursor is opaque: pass
nextCursorback as it came. One this list did not hand out is a 400invalid_cursor.
Şurada da var
webhooks.listAllWorkspaceActivity()
Collect the whole webhook audit log into one array
listAllWorkspaceActivity(options?: WebhookWorkspaceActivityListOptions): Promise<Array<WebhookActivityResource>>Walks every page of listWorkspaceActivity under the same filters and resolves with every change, newest first.
Parametreler
options.endpointIdsArray<string>Endpoint ids to read, at most 50, sent comma-separated. Left out, every endpoint in the workspace.
options.sinceDate | stringOnly rows at or after this instant. A
Dateis sent as ISO 8601, and a string must already be one.options.untilDate | stringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitnumberPage size for each request, 1 to 100. The server defaults to 25.
options.cursorstringStarts the walk from this cursor instead of the newest row.
options.signalAbortSignalCancels the request in flight and the walk with it.
options.apiKeystringOverrides the client API key for every page of this walk.
Döndürür
Array<WebhookActivityResource>, newest first.
Örnek
const changes = await openemail.webhooks.listAllWorkspaceActivity({ since: new Date('2026-09-01T00:00:00Z') }) console.log(changes.filter((change) => change.actor?.kind === 'apiKey').length, 'changes made by keys')Notlar
If any page fails the promise rejects and the rows already fetched are discarded.
Şurada da var
webhooks.iterateWorkspaceActivity()
Stream the whole webhook audit log one change at a time
iterateWorkspaceActivity(options?: WebhookWorkspaceActivityListOptions): AsyncGenerator<WebhookActivityResource, void, undefined>An async generator over listWorkspaceActivity under the same filters, fetching a page only when the one before is drained.
Parametreler
options.endpointIdsArray<string>Endpoint ids to read, at most 50, sent comma-separated. Left out, every endpoint in the workspace.
options.sinceDate | stringOnly rows at or after this instant. A
Dateis sent as ISO 8601, and a string must already be one.options.untilDate | stringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitnumberPage size per request, 1 to 100. The server defaults to 25.
options.cursorstringStarts the walk from this cursor instead of the newest row.
options.signalAbortSignalCancels the request in flight and ends the iteration.
options.apiKeystringOverrides the client API key for every page of this walk.
Döndürür
AsyncGenerator<WebhookActivityResource, void, undefined> yielding one change per step.
Örnek
for await (const change of openemail.webhooks.iterateWorkspaceActivity()) { if (change.type === 'removed') console.log(change.endpointLabel, 'was removed by', change.actor?.label)}Şurada da var
webhooks.listEvents()
List the events an endpoint can subscribe to
listEvents(options?: RequestScope): Promise<WebhookCatalogueResource>Returns every event an endpoint can name in eventTypes, each with a sentence saying when it fires, and the limits an endpoint is held to: how many endpoints the workspace may have, which its plan decides, and how many addresses and domains one allowlist may name.
An endpoint that names no events receives every email event except email.replied, so email.replied and the domain, suppression, file and form families only reach an endpoint that asks for them by name.
Parametreler
options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
WebhookCatalogueResource with events, maxEndpoints, maxAddresses and maxDomains.
Örnek
const catalogue = await openemail.webhooks.listEvents() for (const event of catalogue.events) console.log(event.id, event.label)console.log(`up to ${catalogue.maxEndpoints} endpoints`)Notlar
The same events are exported as
WEBHOOK_EVENTS, so a build that only needs the ids can skip the call.Retried automatically on network failure, since it only reads.
Şurada da var
webhooks.stats()
Read how webhook deliveries went inside a window
stats(options?: WebhookStatsOptions): Promise<WebhookStatsResource>Returns the numbers behind the Analytics tab of the Webhooks page: how many delivery attempts were made, how many were delivered and how many failed, the median time a receiver took to answer, a series of buckets, the events sent and the response codes received.
It covers every endpoint, or the ones endpointIds names. Each try of an event counts as one attempt, so an event retried three times counts three times. The window runs from since to until, and left out it is the 30 days before now. grain sets the bucket width and the key shape, YYYY-MM-DD, YYYY-MM-DDTHH or YYYY-MM-DDTHH:MM, and offsetMinutes shifts the boundaries so days break where the reader's day does.
Parametreler
options.endpointIdsArray<string>Only these endpoints, at most 50. Left out, every endpoint.
options.sinceDate | stringThe start of the window, a
Dateor an ISO 8601 instant. Defaults to 30 days beforeuntil.options.untilDate | stringThe end of the window, not included. Defaults to now.
options.grainTrackingGrainBucket width:
minute,hourorday, defaulting today.options.offsetMinutesnumberMinutes east of UTC to bucket in, from -840 to 840, defaulting to 0. Pass
-new Date().getTimezoneOffset()for the local zone.options.signalAbortSignalCancels the request.
options.apiKeystringOverrides the client API key for this call only.
Döndürür
WebhookStatsResource with the window it covered, totals, buckets, events and codes.
Örnek
const stats = await openemail.webhooks.stats({ since: new Date(Date.now() - 7 * 86_400_000), grain: 'day' }) console.log(`${stats.totals.failed} of ${stats.totals.attempts} attempts failed`)console.log(stats.codes)Notlar
bucketsis sparse: a bucket with no attempt has no entry, so a chart must fill the gaps.medianDurationMsis null when nothing was sent in the window.Retried automatically on network failure, since it only reads.