---
updatedAt: 2026-09-30T17:50:34.235Z
---

Fetch the complete documentation index at: https://docs.avvio.xyz/llms.txt. Use this file to discover all available pages before exploring further. Append .md to any documentation page URL to get its markdown version.

# List webhook deliveries

`GET https://api.avvio.xyz/business/api/v1/organizations/{organizationId}/webhook-endpoints/{endpointId}/deliveries`

Lists the 50 most recent delivery attempts for one endpoint, newest
first, with what your server answered.
This is the answer to "did you send me that event" without anyone
having to open a dashboard.

`lastError` carries your server's response when an attempt failed, and
`nextAttemptAt` is when we will try again. Retries back off over roughly
70 hours (nine retries, ±20% jitter); after that the delivery is dead and
only the event feed (`GET /payments/organizations/{orgId}/events`) will
still have it.

Payloads are not returned. Read the event from the feed by `eventId`,
or replay the delivery from the dashboard (one at a time, or every dead
delivery in a window). A replay re-fires under the same `eventId`, so
your deduplication still holds.

## Parameters

- `organizationId` (path, required) — Your organization id.
- `endpointId` (path, required) — From the endpoint listing.

## Example

```bash
curl -s "$AVVIO_BASE_URL/organizations/$organizationId/webhook-endpoints/$endpointId/deliveries" \
  -H "x-api-key: $AVVIO_API_KEY"
```

## Responses

- `200` — Delivery attempts, newest first
- `401` — The key was refused. Nothing ran. - `UNAUTHORIZED`: missing, invalid or revoked, or a key on a route that does not accept one. - `KEY_EXPIRED`: the key passed the expiry it was issued with. Issue a new one; an expired key cannot be rotated. - `KEY_IP_NOT_ALLOWED`: the key is pinned to source addresses and this request came from another.
- `403` — A valid key that may not make this call. Nothing ran. - `FORBIDDEN`: the key belongs to a different organization. - `ACCOUNT_BLOCKED`: API access for your organization is suspended. - `DEVELOPER_FEATURE_DISABLED`: developer tools (webhook endpoints) are off for your organization. `GET /policy` lists `developer` in `features` when they are on.
- `429` — Too many requests. The default ceiling is **100 requests per minute per API credential** on a 60-second window. High-volume payout and reconciliation routes declare a 600/minute override, and batch submission a 30/minute ceiling. A separate 2,000/minute per-source-IP abuse ceiling always applies. Obey `Retry-After`; it is in seconds and is authoritative. A 429 means the request was refused before the handler ran. Retry reads normally; retry an idempotent mutation with its same `Idempotency-Key`.

Machine contract: [partner-payouts.openapi.yaml](/partner-payouts.openapi.yaml), operation `listWebhookDeliveries`.
