webhooks.deliveries.list
One endpoint's delivery log
GET/webhooks/{id}/deliveries
Every delivery attempted to this endpoint, newest first: which event, how many attempts, what the receiver answered and how long it took. There is no retry operation — delivery is at-least-once with six automatic attempts, and a seventh on demand would be a different promise from the one the signature headers make.
curl 'https://api.gogoscreen.com/api/v1/webhooks/3f2b0c1a-9d4e-4a61-b8c2-000000000014/deliveries?limit=2' \
-H "Authorization: Bearer $GOGOSCREEN_API_KEY"{
"data": [
{
"id": "3f2b0c1a-9d4e-4a61-b8c2-000000000015",
"endpointId": "3f2b0c1a-9d4e-4a61-b8c2-000000000014",
"eventId": "3f2b0c1a-9d4e-4a61-b8c2-000000000016",
"eventType": "webhook.test",
"attempt": 1,
"status": "succeeded",
"responseStatus": 200,
"responseMs": 123,
"lastError": null,
"nextAttemptAt": null,
"deliveredAt": "2026-09-21T11:17:00.000Z",
"createdAt": "2026-09-21T11:17:00.000Z",
"updatedAt": "2026-09-21T11:17:00.000Z"
}
],
"nextCursor": null
}At a glance
| Fact | Detail |
|---|---|
| Scopes | webhooks:manage |
| Credentials | a signed in dashboard session or an API key. |
| Rate limit | 120 requests a minute per credential, in the write class. |
| Idempotency | Not applicable. This operation changes nothing. |
| MCP tool | webhooks_deliveries_list |
| Always sets | Cache-Control: private, no-store |
| Audit | Every call is written to the audit log as webhook_management. |
200 OK
One endpoint's delivery log
| Name | Type | Description | ||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| data | object[] | |||||||||||||||||||||||||||||||||||||||||||
13 fields inside data
| ||||||||||||||||||||||||||||||||||||||||||||
| nextCursor | string | null | Pass as cursor for the next page; null on the last page. | ||||||||||||||||||||||||||||||||||||||||||
| Header | Meaning |
|---|---|
Cache-Control | Always private, no-store. |
Errors
Every refusal is { error: { code, message, details?, requestId } }. Branch on code, never on the sentence. The full catalogue is at Errors.
| Code | Status | When it happens | What to do |
|---|---|---|---|
| invalid_cursor | 400 | The cursor query parameter was not one this API minted, or it was edited, or it is older than a hundred years either way. | Drop the cursor and start the walk from the first page. Pass back exactly the nextCursor string you were given and never build one by hand. |
| validation_failed | 400 | The merged path, query and body did not match the operation's schema. The schemas are strict, so an unknown field is a failure rather than something ignored, and a string carrying half of a character is refused before it can be stored. | Read details.issues. Each entry carries a path, a message and a machine readable code. Fix every named field and send the request again; the same body always fails the same way. |
| unauthorized | 401 | No credential was presented, or the key is unknown, revoked or expired, or an X-API-Key header carried something that is not an API key. details.reason says which. | Send Authorization: Bearer gsk_live_…. A revoked or expired key never starts working again, so issue a new one in the developer console. Put a dashboard session token in Authorization, never in X-API-Key. |
| forbidden_scope | 403 | The credential does not carry every scope the operation declares, or it is the wrong kind of credential for it. keys.* and assistant.* are user only and can never be called by a key. | details.requiredScopes and details.missingScopes name what is missing. A key's scopes cannot be changed after it is issued, so create a new key with them. When details.allowedActors is present, no key can call this operation at all. |
| not_found | 404 | No resource of that id belongs to this account. A resource that belongs to somebody else answers 404 as well, never 403. | Check the id. Do not treat this as a permissions problem. |
| rate_limited | 429 | The credential's per minute budget, the account's per minute ceiling, or a daily cap was exceeded. details.scope is minute, day or account, or global when the product's own daily cap on voice previews is spent. | Wait the Retry-After seconds and retry. details.limit and details.resetAt say what was hit and when it reopens. The RateLimit-* headers on every answer let a client pace itself before it gets here. |
| internal_error | 500 | An unhandled failure inside this API. The original message is logged and never answered. | Retry once, then quote requestId to support. A 5xx deletes the idempotency claim rather than storing it, so retrying under the same key is safe. |