---
title: Webhook events
description: "Every webhook event AI Inbx sends: one page per event with its payload schema, the signature headers, the answer that settles it, and an example body."
sidebar:
  label: Overview
---

{/* Generated by scripts/openapi.ts from the shared API contract. */}

What an endpoint receives: one request per event, each signed, in the envelope every event shares.

## Events

| Event | Fires when |
| --- | --- |
| [`email.received`](/api/endpoints/webhook-events/email-received) | Inbound mail arrived and was matched onto a thread, once per received message. |
| [`email.sent`](/api/endpoints/webhook-events/email-sent) | A message was handed to the mail provider: acceptance, not delivery. |
| [`email.delivered`](/api/endpoints/webhook-events/email-delivered) | The receiving server accepted the message, reported per recipient. |
| [`email.bounced`](/api/endpoints/webhook-events/email-bounced) | Delivery to one or more recipients failed; a hard bounce writes a suppression. |
| [`email.complained`](/api/endpoints/webhook-events/email-complained) | A recipient marked the message as spam, which weighs on sending reputation. |
| [`email.failed`](/api/endpoints/webhook-events/email-failed) | The mail provider refused the message before any delivery attempt. |
| [`email.unsubscribed`](/api/endpoints/webhook-events/email-unsubscribed) | A recipient opted out by link, one-click header, or reply. |
| [`email.opened`](/api/endpoints/webhook-events/email-opened) | A tracked open was recorded, with bot and privacy-proxy hits flagged. |
| [`email.clicked`](/api/endpoints/webhook-events/email-clicked) | A tracked link was clicked, with bot and scanner hits flagged. |
| [`thread.created`](/api/endpoints/webhook-events/thread-created) | A new conversation started: an inbound message, a send, or a forward. |
| [`domain.verified`](/api/endpoints/webhook-events/domain-verified) | A domain's DKIM identity was verified, and the domain can send. |
| [`domain.lost`](/api/endpoints/webhook-events/domain-lost) | A verified domain's DKIM record stopped resolving. |
| [`mailbox.connected`](/api/endpoints/webhook-events/mailbox-connected) | A customer finished authorizing a Gmail or Outlook mailbox. |
| [`mailbox.needs_reauth`](/api/endpoints/webhook-events/mailbox-needs-reauth) | A mailbox's stored authorization stopped working. |
| [`mailbox.disconnected`](/api/endpoints/webhook-events/mailbox-disconnected) | A mailbox was removed, by you or by the customer revoking access. |

Check each delivery's signature before trusting it: see [Verifying](/webhooks/verifying).
