A valid request URL is required to generate request examples{
"received": true,
"outcome": "<string>"
}{
"error": {
"code": "invalid_signature"
}
}{
"error": {
"code": "payload_too_large",
"message": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "not_settled"
}
}Where the identity provider delivers
NOT AN ENDPOINT YOU CALL. The identity provider posts here, and today this does one thing: it sends the sign-up verification email, in plain text, when the provider’s own template is set not to deliver.
NO CREDENTIAL OF OURS AUTHENTICATES IT, because the sender holds none. A delivery is authenticated by a signature over the raw body, carried in three svix-* headers and checked before the body is parsed.
WHAT THE STATUS CODES MEAN. 200 is settled and should not be delivered again, including the outcomes that could not send anything, because a repeat carries the same payload. 400 is a delivery that was not authentic or not readable, and nothing was sent. 503 is a send that failed in a way worth repeating. A repeat of a delivery whose email already went out does not send a second one.
A body over 262144 bytes is refused as it streams.
IT IS ABSENT ON A DEPLOYMENT WITHOUT A SIGNING SECRET OR WITHOUT AN EMAIL SENDER, and in local mode.
Hosted deployments only. A local checkout does not mount this route, so calling it there is a 404.
A valid request URL is required to generate request examples{
"received": true,
"outcome": "<string>"
}{
"error": {
"code": "invalid_signature"
}
}{
"error": {
"code": "payload_too_large",
"message": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "not_settled"
}
}Body
The provider's own event envelope, byte for byte as it sent it. Read only once the signature matches.
Response
Settled. Also the answer when nothing could be sent and a repeat would not change that; those raise an operator alarm here instead of being handed back for redelivery.