Delivery and retries
What counts as delivered
- An HTTP
2xxwithin 10 seconds - The response body is ignored (except for
endpoint.verification) 3xxredirects are not followed and count as failures; configure the final URL directly
Retry schedule
| Attempt | Delay | Elapsed |
|---|---|---|
| Retry 1 | 1 minute | 1 minute |
| Retry 2 | 5 minutes | 6 minutes |
| Retry 3 | 30 minutes | 36 minutes |
| Retry 4 | 2 hours | about 2.6 hours |
| Retry 5 | 6 hours | about 8.6 hours |
| Retry 6 | 12 hours | about 20.6 hours |
After all retries fail, the event is marked failed and its content is deleted 24 hours after creation. Contact us within that window if you need a redelivery.
At-least-once
An event may arrive more than once (for example, your endpoint processed it but the response timed out). Deduplicate by webhook-id or data.scan_id.
Ordering
Events to the same endpoint are not ordered. Sort by data.scanned_at when order matters.
Automatic disabling
An endpoint that keeps failing for more than 3 days is disabled automatically; the App and portal show its status. After fixing it, tap Verify in the App or portal to re-enable.
Delivery log
The App and portal show the last 7 days of deliveries: time, status code, duration and error. Logs never include scan content.
Error codes
| Code | Meaning |
|---|---|
http_error | The endpoint returned a non-2xx status |
redirect_not_followed | The endpoint returned 3xx |
timeout | No response within 10 seconds |
network_error | Could not connect (DNS, TLS, refused) |
url_rejected:private_address | The URL resolved to a non-public IP and was not called |
endpoint_not_verified | The URL changed and has not been verified again |
Rate limits
Each user can upload up to 120 times a minute and 5,000 scans a day. Contact us for higher limits.