Skip to main content
POST /replay/:webhookId/:itemId re-sends a previously captured webhook event to a destination URL you specify. The server validates the target against SSRF rules, strips masked and transport headers, injects replay-specific headers, and returns the target’s response code and body. Authentication: Required when authKey is configured.

Path parameters

string
required
The webhook ID that owns the captured event.
string
required
The log entry ID to replay. If this does not resolve to a log ID but parses as a timestamp, the handler attempts a fallback lookup by timestamp within the specified webhook.

Query parameters

string
required
Destination URL to replay the event to. Subject to SSRF and DNS safety checks. Private networks, loopback addresses, and cloud metadata endpoints are blocked. See Error responses for the full blocked-range list.

Example request

Added headers

The server injects the following headers into every outbound replay request:

Stripped headers

Masked headers (e.g. Authorization, Cookie) and transport-managed headers (e.g. host, content-length) are removed before forwarding. The response body lists any headers that were stripped.

Success response

When headers were stripped, the response also includes:

Error responses

Missing destination URL:
SSRF or DNS validation failure:
Timeout after all retry attempts (504):

Retry and timeout settings

You can tune replay behavior in Actor input: When all retry attempts time out, the server returns 504 Gateway Timeout with a machine-readable code field when one is available.