WEBHOOKS_MANAGE - held by compliance officers and admins in Control, and by every tenant API key - reads it back and can send it again.
Inspect a delivery
event_id, event_type, status, attempts, last_response_status, last_error, next_attempt_at, created_at, updated_at - with:
payload: the JSON body that was sent, parsed, for reading;payload_json: the exact bytes that were sent, as a string. This is what the signature covered and what a resend sends again;endpoint:endpoint_id,urlandactivefor the destination, when it is still configured;signature_headerandevent_id_header: the header names a receiver checks.
payload_json byte for byte.
Send it again
resent_from_delivery_id) and names who asked (requested_by). The receiver gets the same Esectra-Event-Id and the same bytes under a signature made now, so its replay window sees a fresh request and its deduplication sees a repeat. The original delivery’s record is not changed; the new one has its own attempts and is retried by the worker like any other.
Idempotency-Key is required. Replaying a key answers 200 with the delivery the first call made, so a double click or a retried request produces one delivery. A key reused for a different delivery answers 409 IDEMPOTENCY_KEY_REUSED; one held by a request still running 409 RESEND_IN_PROGRESS.
A resend to a disabled endpoint is refused with 409 WEBHOOK_ENDPOINT_DISABLED - disabling means deliveries stop, manual ones included - and to a removed one with 409 WEBHOOK_ENDPOINT_MISSING. Another tenant’s delivery is 404 WEBHOOK_DELIVERY_NOT_FOUND.
Every resend is an audit event, WEBHOOK_RESEND_REQUESTED, under the person or key that asked, naming the original and the new delivery.
