Skip to content
Esc
  • OverviewGuidesWhat exists today, and where to start.
  • QuickstartGuidesKey, domain, first send — in that order.
  • AuthenticationGuidesBearer keys, the mandatory User-Agent, and what each refusal means.
  • ErrorsGuidesThe whole vocabulary, with the status each name carries.
  • IdempotencyGuidesRetry a send without sending it twice.
  • PaginationGuidesCursors are item IDs, not page numbers.
  • Rate limitsGuidesTen a second per team, and the headers that tell you where you are.
  • EventsGuidesEvery event a webhook can carry, with one real payload each.
  • DomainsGuidesThe records, where they go at each registrar, and what the page does while you wait.
  • TrackingGuidesOpens and clicks: one record, two toggles, and what an open really means.
  • ReceivingGuidesInbound mail, and the Inbox: a webhook fires, you read it, you answer it.
  • InboxGuidesChannels, personal mailboxes and seats: who sees what, and where a reply goes.
  • Node SDKGuidesThe rasket package: typed from the API's own document, retries only what is safe.
  • Python SDKGuidesThe rasket package on PyPI: the Node client's methods, in snake_case, over httpx.
  • MCP serverGuidesConnect Claude, ChatGPT or any MCP client: your scopes, no key.
  • AI assistGuidesSubject lines, drafts and diagnosis — in the dashboard and over the API, off until you allow it.
  • AgentsGuidesLet an AI agent set Rasket up: the skill, the rules file, MCP, and the recipe they share.
  • OAuthGuidesLet another app act for a team: register, authorize with PKCE, exchange, refresh.
  • Single sign-onGuidesOIDC login for your team, a domain proved by DNS, enforcement and break-glass.
  • IntegrationsGuidesVercel, Netlify and Cloudflare, plus Zapier and n8n for workflows without code.
  • SMTPGuidesSend from anything that speaks SMTP: settings, setup guides, limits and replies.
  • ZapierGuidesSend email, add contacts and react to email events from a Zap, with no code.
  • n8nGuidesThe Rasket node and trigger for n8n workflows: install, connect, every operation.
  • VercelGuidesAdd Rasket on Vercel: a Sending key in each project as RASKET_API_KEY, no copying.
  • EmailsAPI referenceSend, batch, retrieve, list, reschedule, cancel, attachments.
  • DomainsAPI referenceAdd a domain, publish its records, verify it.
  • API keysAPI referenceCreate, list, rename and revoke credentials.
  • WebhooksAPI referencePayloads, signature verification, retries and replay.
  • SuppressionsAPI referenceAddresses we will not send to, and why.
  • LogsAPI referenceEvery request made with this team's credentials.
  • MetricsAPI referenceDelivery, bounce, complaint and engagement counts.
  • TemplatesAPI referenceVersioned email content with typed variables, addressed by ID or alias.
  • ContactsAPI referenceYour audience: contacts, their typed properties, segments and topic choices.
  • SegmentsAPI referenceAudiences defined by a filter, by hand, or both.
  • TopicsAPI referenceWhat contacts subscribe to, and the preference page's list.
  • CampaignsAPI referenceCampaigns, at /broadcasts: one message to a segment, from draft to results.
  • ImportsAPI referenceCSV uploads: column mapping, conflicts and counts.
  • AutomationsAPI referenceWorkflows that run per contact: the graph, its versions, and every run.
  • Custom eventsAPI referenceThe names your product fires, and what starts a workflow.
  • ReceivingAPI referenceMail sent to you: the message, its attachments, its raw source.
  • OAuthAPI referenceClient registration, the token endpoint, and the grants a team has given.
  • TeamAPI referenceThe team a credential belongs to: its plan, sender identity, AI flag and members.
  • BillingAPI referencePlan, usage, invoices and add-ons, and the hosted pages where a customer pays.
  • AI helpersAPI referenceSubject lines, a first draft, and why an email did what it did.

API referenceLogs

Logs

Every request made with this team's credentials, with the status it answered and how long it took. This is where a send that went wrong is diagnosed.

Who can read them

Both endpoints need a full_access key. A sending_access key is refused with 401 restricted_api_key — the key is valid, it simply does not reach this endpoint. A revoked key of either kind is 403 restricted_api_key instead, which is a different problem with the same name; the status is what tells them apart, and the errors page lists both.

What is in a log

  • The request line — method, endpoint, response status, latency and the User-Agent you sent.
  • request_id, which is also in the message of any 500 you received, so an error you are holding leads straight to the log of the call that produced it.
  • api_key_id, so a request can be traced to the credential that made it, and email_id when the request created one.

Stored bodies are measurements, not your message. A body naming a password, token or key was dropped whole rather than partly hidden, and a send's content was replaced by its size and digest. Nothing here can give you back what you sent.

Where a request came from

Where a logged request came from
sourceMeans
apiYour own code, calling this API with a key.
dashboardA write made from the dashboard. The dashboard calls this same API, so its writes are logged too.
sdk:<name>One of our client libraries, which names itself here.

Reading this endpoint is itself a request, and is logged. The newest entry on a fresh call is usually that call.

How long they are kept

Logs are kept for your plan's retention window — 30 days on the free plan — and are then deleted. A request older than that is gone rather than empty, and a log belonging to another team answers 404 not_found, the same answer as one that never existed.

Endpoints

List request logs

GET /logs

Every request made with this team's credentials, newest first.

Query parameters

  • statusinteger

    The response status recorded on the request, such as 422.

  • sourcestring

    Where the request came from: api, dashboard, or sdk:<name> for one of our clients.

  • searchstring

    Text in the endpoint (/emails/{email_id}) or in the path that was requested, so an email ID finds the requests that named it. Case-insensitive, 1–200 characters.

  • limitinteger

    How many logs to return, 1–100. Defaults to 20.

6 more fields (exclude_source, user_agent, start_date, end_date, after, before)
  • exclude_sourcestring

    Leave out one source, spelled as source is. dashboard shows every request your own code made.

  • user_agentstring

    An exact User-Agent, as it was sent. Not a substring match.

  • start_datestring

    ISO 8601 instant, inclusive. A calendar date alone is 422 invalid_parameter — send 2026-09-09T00:00:00.000Z.

  • end_datestring

    ISO 8601 instant, inclusive. Must be at or after start_date, or the request is 422 invalid_parameter.

  • afterstring

    Return the page that follows this log ID. Mutually exclusive with before.

  • beforestring

    Return the page that precedes this log ID. Mutually exclusive with after.

Request

curl -X GET "https://api.rasket.com/logs?status=422&limit=20" \
  -H "Authorization: Bearer $RASKET_API_KEY" \
  -H "User-Agent: acme-billing/1.0"

Response 200

{
  "object": "list",
  "has_more": false,
  "data": [
    {
      "id": "0198f4c1-0000-7000-8000-000000000000",
      "created_at": "2026-09-09T10:16:44.902Z",
      "endpoint": "/emails",
      "method": "POST",
      "response_status": 422,
      "user_agent": "acme-billing/1.0",
      "source": "api",
      "request_id": "req_0198f4c1000070008000000000000000",
      "latency_ms": 41,
      "api_key_id": "a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75"
    }
  ]
}
  • Needs a full-access key. A sending-only key is refused with 401 restricted_api_key.
  • Writes made from the dashboard go through this same API and are logged with source: dashboard, so the list is every write to your data rather than only the ones your code made.
  • Reading this endpoint records a request of its own, so the newest entry on a fresh call is usually that call.
  • Logs are kept for your plan's retention window — 30 days on the free plan — and then deleted. A request older than that is gone, not empty.

Retrieve a request log

GET /logs/{log_id}

One request in full, with the bodies that were stored for it.

Path parameters

  • log_idstringRequired

    The ID of the log.

Request

curl -X GET "https://api.rasket.com/logs/0198f4c1-0000-7000-8000-000000000000" \
  -H "Authorization: Bearer $RASKET_API_KEY" \
  -H "User-Agent: acme-billing/1.0"

Response 200

{
  "object": "log",
  "id": "0198f4c1-0000-7000-8000-000000000000",
  "created_at": "2026-09-09T10:16:44.902Z",
  "endpoint": "/emails",
  "method": "POST",
  "response_status": 422,
  "user_agent": "acme-billing/1.0",
  "source": "api",
  "request_id": "req_0198f4c1000070008000000000000000",
  "latency_ms": 41,
  "api_key_id": "a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75",
  "request_body": {
    "from": "billing@example.com",
    "subject": "Invoice",
    "html_bytes": 812
  },
  "response_body": {
    "statusCode": 422,
    "name": "missing_required_field",
    "message": "to is required."
  },
  "email_id": null
}
  • request_body is the body as it was stored, not as it was sent. A body naming a password, token or key was dropped whole rather than partially hidden; a send's message content was replaced by its measurements, so html and text appear as byte counts and each attachment as its filename, size and SHA-256. There is no way to recover the original.
  • response_body is present for a failed request only. A successful call returns null — you already have that body.
  • email_id links the log to the email the request created, when it created one. A batch send creates many and links none.
  • A log belonging to another team is 404 not_found, the same answer as a log that never existed.