A valid request URL is required to generate request examples{
"deliveries": [
{
"deliveryId": "<string>",
"webhookId": "<string>",
"event": "run.ended",
"status": "pending",
"attempts": 123,
"responseStatus": 123,
"error": "<string>",
"payloadPreview": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"lastAttemptAt": "2023-11-07T05:31:56Z",
"nextAttemptAt": "2023-11-07T05:31:56Z"
}
],
"nextBefore": "<string>"
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "not_found",
"message": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}What was delivered, and what happened
Every delivery attempted for one subscription, newest first: the event, when it was tried, what your endpoint answered, how many attempts it has had, and when the next one is due.
A delivery id in another org answers 404, the same 404 an id that names nothing gets, so this is not an existence oracle.
Hosted deployments only. A local checkout does not mount this route, so calling it there is a 404.
A valid request URL is required to generate request examples{
"deliveries": [
{
"deliveryId": "<string>",
"webhookId": "<string>",
"event": "run.ended",
"status": "pending",
"attempts": 123,
"responseStatus": 123,
"error": "<string>",
"payloadPreview": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"lastAttemptAt": "2023-11-07T05:31:56Z",
"nextAttemptAt": "2023-11-07T05:31:56Z"
}
],
"nextBefore": "<string>"
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "not_found",
"message": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Authorizations
The control surface credential. Send Authorization: Bearer <token>.
Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.
Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.
Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.
Path Parameters
The subscription.
Query Parameters
How many to return, 1 to 100. Defaults to 50. Above the maximum is refused, never quietly reduced.
1 <= x <= 100Opaque cursor from a previous page's nextBefore. Treat it as opaque. Send it only when you have one: an empty value is refused rather than read as no cursor.