# Request logs

> Inspect every API v2 request and SMTP transaction made with your API keys, including request and response bodies, to debug 4xx errors.

**Email API → Logs** records the API and SMTP traffic that reaches Emailit with your API keys. When a send fails before an email is even created, for example because of a validation error or a rate limit, the request log is where you see what your code sent and exactly what Emailit answered.

## What's logged

The page header sums it up: "Successful and failed API v2 and SMTP requests authenticated with an API key."

| Source | What's recorded |
| --- | --- |
| **API** | Every request to `https://api.emailit.com/v2/…` that Emailit can tie to your workspace: method, path, status code, duration, API key, IP address, user agent, and the request and response bodies. |
| **SMTP** | Each `DATA` command, with the result (`250 2.0.0 OK: queued as em_…` or the error), the envelope sender, recipients, headers and message size. Also `MAIL FROM` rejections caused by rate limits (`452`) and failed `AUTH` attempts with a revoked API key (`535`). |

Not logged:

- Requests with a missing or unknown API key, because they can't be linked to a workspace. If you get `401 Invalid API key` and see nothing here, check which key your code uses.
- Activity in the dashboard, and successful SMTP `AUTH` commands.

Sensitive values are redacted before storage. Fields named like `password`, `secret`, `token`, `authorization` or `api_key`, and values that look like API keys (`secret_…`) or tokens, are replaced with `[redacted]`. Long strings are truncated at 16,384 characters and arrays at 50 items, so large attachments don't appear in full.

## Find a request

- **Time range:** choose **Last 1 hour**, **Last 6 hours**, **Last 24 hours** (default), **Last 72 hours**, **Last 7 days** or **Last 30 days**, or pick a custom date range. You can also drag across the chart to zoom into a period.
- **Chart:** successful and failed requests over time, so you can spot when errors started.
- **Search:** matches the path, message, method or status.
- **Filters:** **Source** (API or SMTP), **Outcome** (Success or Error), **Method**, **Path**, **Message**, **Status code**, **Duration**, **Created** and **API key**.

The table shows **Timestamp**, **Level** (Success for status codes below 400, Error otherwise), **Source**, **Method**, **Message** (for example `POST /v2/emails → 422`), **Status** and **Duration**.

## Read a request

Select a row to open it. The page shows:

- **Created**, **Level**, **Source** and **Status**.
- **Request body:** the JSON your code sent, or for SMTP the command, envelope and message summary.
- **Response body:** what Emailit returned, including error details.
- **Details:** the log ID, path, duration, API key ID (`credential_id`), IP address, user agent and request ID.

## Debug 4xx errors

1. **Filter to errors.** Set **Outcome** to Error, or **Status code** to the code you got, and choose a range that covers the failure.

2. **Open the request and read the response body.** Emailit's error bodies say what went wrong. Validation errors list each problem in `validation_errors` or `details`.

3. **Compare with the request body.** Check the fields Emailit received. Typical surprises are a missing `from` domain, `to` sent as an object, or a `scheduled_at` in an unexpected format.

4. **Match the fix to the status code.**

   | Status | Common cause | Where to read more |
   | --- | --- | --- |
   | `400` | Malformed JSON or a validation error. | [Errors](/docs/api-reference/errors/) |
   | `401` | Missing or invalid API key. Unknown keys aren't logged. | [Authentication](/docs/api-reference/authentication/) |
   | `402` | Not enough credits for the send. | [Credits](/docs/billing/credits/) |
   | `403` | The workspace isn't verified and a recipient isn't a member (`unverified_workspace_recipient`), the key is restricted to another domain, the feature needs a higher plan (`plan_required`), or the workspace is suspended. | [Production access](/docs/workspaces/production-access/) |
   | `409` | A duplicate, or a request with the same `Idempotency-Key` still in progress. | [Idempotency](/docs/api-reference/idempotency/) |
   | `413` | The message is larger than 40 MB. | [Attachments](/docs/email-api/attachments/) |
   | `422` | The request is valid but can't be done, for example retrying an email that isn't retryable. | [Errors](/docs/api-reference/errors/) |
   | `429` | Per-second or daily sending limit reached. The body includes `limit`, `current` and `retry_after`. | [Rate limits](/docs/api-reference/rate-limits/) |

   For SMTP, the same problems appear as SMTP reply codes, for example `530` when the From domain isn't verified or `452` for rate limits. See [SMTP troubleshooting](/docs/smtp/troubleshooting/).

5. **Fix and resend.** A request that failed with a `4xx` didn't create an email, so it's safe to send again once fixed.

If the request succeeded here but the email didn't arrive, the problem happened later. Find the email in **Email API → Emails** and read its [delivery attempts](/docs/logs/email-details/#deliveries-loads-and-clicks).

## Retention

Request logs follow the **Logs** retention window:

| | Pay as you go | Pro | Business | Custom |
| --- | --- | --- | --- | --- |
| Request logs kept | 7 days | 30 days | 30 days | Flexible |

Request logs are only available in the dashboard; there's no API endpoint for them.

## Related

  - [API errors](/docs/api-reference/errors/)
  - [SMTP troubleshooting](/docs/smtp/troubleshooting/)

---
Source: https://emailit.com/docs/logs/request-logs/
