Skip to main content
Two lists in the API can grow without bound and are paged with a cursor. Any POST can be made safe to retry with an Idempotency-Key header. This page covers both.

Pagination

Which lists are paged

Every other list returns everything in one response. Download receipts return the 200 most recent events.

How it works

  • Pass limit to set the page size, from 1 to the largest page above. Anything else returns 400 invalid_request.
  • Each page returns nextCursor. Pass it back unchanged as cursor to get the next page.
  • nextCursor is null on the last page.
  • Treat the cursor as opaque. Never build or edit one; a cursor the API did not issue returns 400 invalid_request.
Webhook events are the exception to the last-page rule: nextCursor is returned on every page, so a poller can resume from it later, and hasMore tells you whether there is more now. Webhooks covers polling a pull endpoint.

Walk every page

A page looks like this:
For collection files, use allCollectionFiles(id) in JavaScript or all_collection_files(id) in Python the same way.

Idempotency

A network failure can hide whether a request succeeded. Retrying a GET or DELETE is always safe. Retrying a POST could create something twice, unless you send an Idempotency-Key.

Send a key

Generate a fresh UUID for each logical request, and send the same UUID on every retry of that request:
The SDKs do this for you: every POST carries an Idempotency-Key, reused on each of its retries.

What happens on a retry

Rules

  • Only POST reads the header. Other methods ignore it.
  • A key is remembered for 24 hours after its first use.
  • Idempotency keys are scoped to the workspace. Two API keys in the same workspace share them.
  • A key is bound to the request: its method, path and exact body. Reusing it for anything else gets idempotency_key_reused.
  • The format is 1 to 255 printable ASCII characters, with no spaces. A UUID works. Anything else returns 400 invalid_request.

Requests that are safe to retry without a key

  • Sending a transfer. Finalizing an already-sent transfer does not send it again or email anyone twice.
  • Creating a transfer makes a new draft each time. A draft that is never sent is deleted after 24 hours, so a duplicate costs nothing, but a key avoids it.

Next steps

Errors

Which errors to retry, and how.

Limits

Rate limits and the RateLimit headers.