> ## Documentation Index
> Fetch the complete documentation index at: https://docs.truthlocks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List deliveries

> Returns delivery history for a webhook endpoint.

Returns the most recent delivery attempts for a webhook endpoint (up to 50). Use this to monitor delivery health, debug failures, and verify that events are reaching your server.

### Parameters

<ParamField path="id" type="uuid" required>
  The ID of the webhook endpoint
</ParamField>

### Delivery statuses

| Status      | Description                                                |
| :---------- | :--------------------------------------------------------- |
| `pending`   | Delivery is queued and has not been attempted yet          |
| `delivered` | Your endpoint returned a 2xx status code                   |
| `failed`    | Delivery failed but may be retried                         |
| `dead`      | All retry attempts exhausted — delivery permanently failed |

### Response fields

| Field             | Type      | Description                                                                |
| :---------------- | :-------- | :------------------------------------------------------------------------- |
| `id`              | `uuid`    | Unique identifier for the delivery attempt                                 |
| `endpoint_id`     | `uuid`    | The webhook endpoint this delivery belongs to                              |
| `event_id`        | `string`  | Unique event identifier — use this to deduplicate retried events           |
| `event_type`      | `string`  | Event type that triggered the delivery (e.g., `attestation.created`)       |
| `payload_hash`    | `string`  | SHA-256 hash of the delivered payload                                      |
| `status`          | `string`  | Current delivery status: `pending`, `delivered`, `failed`, or `dead`       |
| `attempt_count`   | `integer` | Total number of delivery attempts so far                                   |
| `next_attempt_at` | `string`  | ISO 8601 timestamp of the next retry, or `null` if no retry is scheduled   |
| `last_error`      | `string`  | Error message from the most recent failed attempt, or `null` if successful |
| `http_status`     | `integer` | HTTP status code returned by your endpoint, if available                   |
| `created_at`      | `string`  | ISO 8601 timestamp when the delivery was first queued                      |
| `updated_at`      | `string`  | ISO 8601 timestamp of the most recent status change                        |

### Responses

<Note>
  Results are limited to the 50 most recent deliveries, sorted by creation time (newest first). Pagination is not currently supported.
</Note>


## OpenAPI

````yaml mint-openapi.yaml GET /v1/webhooks/endpoints/{id}/deliveries
openapi: 3.0.3
info:
  title: Truthlocks API
  description: >
    Truthlocks is a universal verification infrastructure for documents,
    credentials, and digital assets.

    This specification defines the canonical API for interacting with Truthlocks
    services.


    ## Base URLs

    - **Production**: `https://api.truthlocks.com`

    - **Sandbox**: `https://sandbox-api.truthlocks.com`


    ## Authentication

    - **API Keys**: Use `X-API-Key` header for machine-to-machine operations

    - **Bearer Tokens**: Use `Authorization: Bearer <jwt>` for user-initiated
    operations


    ## Tenant Identity

    In production, tenant identity is derived from the authenticated context
    (API key or JWT).

    The `X-Tenant-ID` header is ignored in production to prevent spoofing.
  version: 1.0.0
  contact:
    name: Truthlocks Support
    url: https://truthlocks.com/support
    email: support@truthlocks.com
servers:
  - url: https://api.truthlocks.com
    description: Production API
  - url: https://sandbox-api.truthlocks.com
    description: Sandbox Environment
security:
  - APIKey: []
tags:
  - name: Authentication
    description: API key and token management
  - name: Issuers
    description: Issuer registration and trust management
  - name: Keys
    description: Cryptographic key management for issuers
  - name: Attestations
    description: Attestation lifecycle (mint, revoke, supersede)
  - name: Verification
    description: Attestation verification and proof bundles
  - name: Governance
    description: Issuer governance workflows (admin only)
  - name: Identity
    description: Organization, user, and role management
  - name: Audit
    description: Audit event queries
  - name: Platform
    description: Platform administration (super admin only)
  - name: Platform Review
    description: Staff review workflows for issuer applications
  - name: Tenant Console
    description: Tenant profile and lifecycle endpoints
  - name: Health
    description: Service health and readiness endpoints
  - name: Risk
    description: Risk signal ingestion and fraud detection
  - name: Risk Enforcement
    description: Risk enforcement actions — block, challenge, quarantine, and configuration
  - name: Billing
    description: Billing, subscription, and addon management
  - name: Machine Identity
    description: >-
      Machine Agent Identity Protocol (MAIP) — agent registration, sessions,
      trust, witness, compliance, orchestration, and observability
externalDocs:
  description: Transparency read-only API (separate service spec)
  url: >-
    https://github.com/truthlocks/truthlock/blob/main/docs/transparency/openapi.yaml
paths:
  /v1/webhooks/endpoints/{id}/deliveries:
    get:
      tags:
        - Webhooks
      summary: List webhook deliveries
      description: Returns delivery history for a webhook endpoint.
      operationId: webhooks.endpoints.deliveries
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
          description: Webhook endpoint ID
        - name: limit
          in: query
          schema:
            type: integer
            default: 20
      responses:
        '200':
          description: Delivery history
          content:
            application/json:
              schema:
                type: object
                properties:
                  items:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                        event_type:
                          type: string
                        status_code:
                          type: integer
                        delivered_at:
                          type: string
                        success:
                          type: boolean
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
      security:
        - APIKey: []
components:
  schemas:
    ErrorEnvelope:
      type: object
      required:
        - code
        - message
        - http_status
      properties:
        code:
          type: string
          description: Machine-readable error code
          enum:
            - AUTH_REQUIRED
            - AUTH_INVALID
            - PERMISSION_DENIED
            - TENANT_IDENTITY_UNVERIFIED
            - NOT_FOUND
            - VALIDATION_ERROR
            - CONFLICT
            - PAYLOAD_TOO_LARGE
            - RATE_LIMIT_EXCEEDED
            - QUOTA_EXCEEDED
            - SERVICE_UNAVAILABLE
            - INTERNAL_ERROR
        message:
          type: string
          description: Human-readable error message
        http_status:
          type: integer
          description: HTTP status code
        retry_after_ms:
          type: integer
          description: Milliseconds to wait before retrying (for rate limits)
        details:
          type: object
          description: Additional error context
      example:
        code: AUTH_REQUIRED
        message: Authentication required
        http_status: 401
  securitySchemes:
    APIKey:
      type: apiKey
      in: header
      name: X-API-Key
      description: API key for machine-to-machine authentication

````