Skip to main content
GET
cURL
Poll the status_url returned by Start webhook verification. This read returns the current state without sending another challenge. Keep polling while state is queued or running, and stop when it becomes terminal.

Parameters

Key response fields

verified means the same endpoint and verification identity accepted a challenge before expiry. A cancelled attempt can indicate an endpoint change or lost owner access. A failed or expired attempt stays terminal; it never restarts when read or replayed. An attempt belonging to another owner, or an endpoint that has been deleted, returns 404. API keys and OAuth tokens with webhooks scope retain the existing webhook access and quota rules.

Example

What it does not return

  • The verification token or signing secret.
  • The receiver response body, resolved address, claim token, or internal error text.
  • A new attempt or another outbound challenge.

Authorizations

Authorization
string
header
required

Legacy default or named integration API key, or OAuth 2.1 access token, in the Authorization header as Bearer oxi_sk_live_... or Bearer oxi_at_.... Default keys retain full access; integration keys are limited to their approved read, webhooks, export and usage scopes and expire within 90 days. All credentials share the owner's account limits. Data calls require an active Pro subscription and return live data. A 401 carries WWW-Authenticate: Bearer resource_metadata="https://api.0xinsider.com/.well-known/oauth-protected-resource" (RFC 6750 section 3, RFC 9728).

Headers

X-Query-Validation
enum<string>

Opt into strict query-name validation. The default is compatible: unknown names are ignored and reported in X-Query-Ignored. With strict, an unknown name returns 400 bad_request with error.reason unknown_query_parameter before the handler runs, including when its percent escape is incomplete.

Available options:
strict

Path Parameters

id
integer<int64>
required

Webhook endpoint id owned by the authenticated API key user.

attempt_id
string<uuid>
required

Verification attempt UUID returned by admission. Must belong to this webhook and account.

Response

Current sanitized attempt state

object
string
required
Allowed value: "webhook_verification_attempt"
data
object
required
meta
object
required