Webhooks
Webhooks
Receive signed HTTP notifications when email, contact, domain, and suppression state changes.
How it works
A webhook is a public HTTPS endpoint that Opensend posts to when something happens in your team. You pick which event types it listens for. Each event is one JSON POST request with Content-Type: application/json and three svix-* headers that sign the body.
json
{
"type": "email.sent",
"created_at": "2026-09-29T10:00:00.000Z",
"data": {
"created_at": "2026-09-29T09:59:59.000Z",
"email_id": "YOUR_EMAIL_ID",
"message_id": "SES_MESSAGE_ID",
"from": "hello@example.com",
"to": ["you@example.net"],
"subject": "Welcome",
"tags": {}
}
}type is the event type. created_at is when Opensend recorded the event. data describes the resource the event is about; its shape depends on the type and is documented on each event page. Every timestamp is an ISO 8601 UTC string. IDs are the same opaque IDs the REST API returns.
Event types
| Group | Types |
|---|---|
email.sent, email.delivered, email.delivery_delayed, email.opened, email.clicked, email.bounced, email.complained, email.received, email.failed, email.scheduled, email.suppressed | |
| Contact | contact.created, contact.updated, contact.deleted |
| Domain | domain.created, domain.updated, domain.deleted |
| Suppression | suppression.added, suppression.removed |
Custom events sent through POST /events/send are not webhook event types. They trigger automations only.
Delivery rules
- Your endpoint has 15 seconds to answer. A
2xxresponse counts as delivered. Anything else, including a redirect, a timeout, or no HTTP response at all, is a failed attempt and is retried. - Every webhook in the team that listens for the type receives the event, with the same
svix-id. - Delivery order is not guaranteed. A retried
email.sentcan arrive afteremail.delivered. Use the timestamps in the payload. - Retries and replays reuse the same
svix-id. Store it and skip duplicates. - Events, deliveries, and attempts are kept for 90 days.
Next steps
- Create a webhook in the dashboard or through the REST API.
- Verify webhook requests before you trust a payload.
- Retries and replays cover the schedule and the delivery log.