> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qa.esectra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Handles `GET /v1/webhooks/deliveries/{delivery_id}`.

> The payload as sent, the destination and the attempt record. Never the
signing secret and never a signature: a header a receiver has already
verified is not something to hand out a second time.

# Errors

`401` without credentials, `403` without `WEBHOOKS_MANAGE`, `404` for an
unknown delivery or another tenant's, `503` when a store cannot be read.



## OpenAPI

````yaml /openapi.json get /v1/webhooks/deliveries/{delivery_id}
openapi: 3.1.0
info:
  title: Esectra API
  description: >-
    Transaction screening, identity verification, and wallet risk.


    Every create route accepts `Idempotency-Key`; replaying one returns the
    original record with `200` where the first call returned `201`. `POST
    /v1/transactions` requires the header, because a duplicated transaction is a
    duplicated financial record.
  license:
    name: proprietary
    identifier: proprietary
  version: 0.1.0
servers: []
security: []
paths:
  /v1/webhooks/deliveries/{delivery_id}:
    get:
      tags:
        - Webhooks
      summary: Handles `GET /v1/webhooks/deliveries/{delivery_id}`.
      description: |-
        The payload as sent, the destination and the attempt record. Never the
        signing secret and never a signature: a header a receiver has already
        verified is not something to hand out a second time.

        # Errors

        `401` without credentials, `403` without `WEBHOOKS_MANAGE`, `404` for an
        unknown delivery or another tenant's, `503` when a store cannot be read.
      operationId: get_delivery_handler
      parameters:
        - name: delivery_id
          in: path
          description: Delivery identifier
          required: true
          schema:
            type: string
      responses:
        '200':
          description: The delivery, its payload and its destination
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DeliveryDetailBody'
        '401':
          description: No usable credentials
        '403':
          description: The caller does not hold WEBHOOKS_MANAGE
        '404':
          description: This tenant has no such delivery
        '503':
          description: A backing store could not be reached
      security:
        - api_key: []
        - session_cookie: []
components:
  schemas:
    DeliveryDetailBody:
      allOf:
        - oneOf:
            - type: object
              description: A delivery as returned to a customer.
              required:
                - delivery_id
                - endpoint_id
                - event_id
                - event_type
                - subject_id
                - status
                - attempts
                - created_at
                - updated_at
              properties:
                attempts:
                  type: integer
                  format: int32
                  description: Attempts made.
                  minimum: 0
                created_at:
                  type: string
                  description: RFC 3339 creation timestamp.
                delivery_id:
                  type: string
                  description: Delivery identifier.
                endpoint_id:
                  type: string
                  description: Endpoint it was sent to.
                event_id:
                  type: string
                  description: Event identifier, stable across attempts.
                event_type:
                  type: string
                  description: Event name.
                last_error:
                  type:
                    - string
                    - 'null'
                  description: Why the last attempt failed.
                last_response_status:
                  type:
                    - integer
                    - 'null'
                  format: int32
                  description: HTTP status of the last attempt.
                  minimum: 0
                next_attempt_at:
                  type:
                    - string
                    - 'null'
                  description: When the next attempt is scheduled.
                requested_by:
                  type:
                    - string
                    - 'null'
                  description: >-
                    Who asked for the resend; absent on a delivery the system
                    made.
                resent_from_delivery_id:
                  type:
                    - string
                    - 'null'
                  description: >-
                    The delivery this one re-sends, when a person asked for it
                    again.
                status:
                  $ref: '#/components/schemas/DeliveryStatus'
                  description: How far the delivery got.
                subject_id:
                  type: string
                  description: Object the event was about.
                updated_at:
                  type: string
                  description: RFC 3339 time of the last change.
          description: The delivery record.
        - type: object
          required:
            - payload
            - payload_json
            - signature_header
            - event_id_header
          properties:
            endpoint:
              oneOf:
                - type: 'null'
                - $ref: '#/components/schemas/DeliveryEndpointBody'
                  description: The endpoint, when it is still configured.
            event_id_header:
              type: string
              description: The header the event id travels in.
            payload:
              description: The JSON body sent to the receiver, parsed, for display.
            payload_json:
              type: string
              description: >-
                The exact bytes sent to the receiver, as a string: what the
                signature

                covered, and what a resend sends again. Field order is the
                event's,

                which a re-encoded `payload` does not preserve.
            signature_header:
              type: string
              description: >-
                The header the signature travels in, so a receiver knows what to
                check.
      description: 'One delivery in full: the record, the payload it carried, where it went.'
    DeliveryStatus:
      type: string
      description: How far a delivery has got.
      enum:
        - PENDING
        - DELIVERED
        - RETRYING
        - EXHAUSTED
    DeliveryEndpointBody:
      type: object
      description: Where a delivery went, as a customer may see it. No secret.
      required:
        - endpoint_id
        - url
        - active
      properties:
        active:
          type: boolean
          description: Whether deliveries to it are still attempted.
        endpoint_id:
          type: string
          description: Endpoint identifier.
        url:
          type: string
          description: Destination URL.
  securitySchemes:
    api_key:
      type: http
      scheme: bearer
      description: >-
        A tenant API key. Acts for exactly one tenant and cannot conclude a
        case, because a conclusion records a person.
    session_cookie:
      type: apiKey
      in: cookie
      name: esectra_session
      description: >-
        A signed-in reviewer's session. httpOnly and SameSite=Lax; set by `POST
        /v1/control/sessions` and only usable once the second factor is met.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.