List outgoing messages
const url = 'https://example.com/api/v1/outbox';const options = { method: 'GET', headers: {cookie: 'bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/outbox \ --cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3EMessages of ours to counterparties (DSP and delegation), newest first. A message is tried again with backoff until it is delivered or too old; then it is failed and waits for an operator to send it again or drop it (decisions #56).
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”pending, delivered, failed or dropped.
Only the messages of this negotiation, transfer or delegation.
At most this many, 1 to 1000; default 100.
Responses
Section titled “Responses”OK.
A page of a list. next_cursor is null on the last page.
object
A row of the outbox: a message of ours to a counterparty, until it is delivered or dropped (decisions #56).
object
The negotiation, transfer or delegation the message belongs to.
Pass as cursor for the next page.
Example generated
{ "items": [ { "id": 1, "process_id": "example", "kind": "example", "message_type": "example", "counterparty_did": "example", "url": "example", "evidence_id": "example", "status": "example", "attempts": 1, "next_attempt_at": "2026-04-15T12:00:00Z", "last_error": "example", "response_status": 1, "created_at": "2026-04-15T12:00:00Z", "resent_at": "2026-04-15T12:00:00Z", "delivered_at": "2026-04-15T12:00:00Z" } ], "next_cursor": "example"}No valid session, DPoP-bound token or API key.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}