v33

latestOpenAPI 3.1.0Proprietaryraw.githubusercontent.com2026-05-28103497709.6 KB
Webhooks

Verification status change

Webhook that is called when a customer's KYC/KYB verification status changes. This endpoint should be implemented by clients of the Grid API.

Authentication

The webhook includes a signature in the X-Grid-Signature header that allows you to verify that the webhook was sent by Grid. To verify the signature:

  1. Get the Grid API public key provided to you during integration
  2. Decode the base64 signature from the header
  3. Create a SHA-256 hash of the request body
  4. Verify the signature using the public key and the hash

If the signature verification succeeds, the webhook is authentic. If not, it should be rejected.

postWebhookverification-update

Payload

idstring required

Unique identifier for this webhook delivery (can be used for idempotency)

type'VERIFICATION.APPROVED' | 'VERIFICATION.REJECTED' | 'VERIFICATION.RESOLVE_ERRORS' | 'VERIFICATION.IN_PROGRESS' | 'VERIFICATION.PENDING_MANUAL_REVIEW' required

Type of webhook event in OBJECT.EVENT dot-notation. The part before the dot identifies the resource, the part after identifies the event. This lets consumers route purely on type without inspecting data.status.

timestampstring date-time required

ISO 8601 timestamp of when the webhook was sent

Example payload

{
  "id": "Webhook:019542f5-b3e7-1d02-0000-000000000007",
  "timestamp": "2025-08-15T14:32:00Z",
  "data": {
    "id": "Verification:019542f5-b3e7-1d02-0000-000000000001",
    "customerId": "Customer:019542f5-b3e7-1d02-0000-000000000001",
    "verificationStatus": "RESOLVE_ERRORS",
    "errors": [
      {
        "resourceId": "Customer:019542f5-b3e7-1d02-0000-000000000001",
        "type": "MISSING_FIELD",
        "field": "customer.address.line1",
        "acceptedDocumentTypes": [
          "PASSPORT"
        ],
        "reason": "Business address line 1 is required"
      }
    ],
    "createdAt": "2025-10-03T12:00:00Z",
    "updatedAt": "2025-10-03T12:00:00Z"
  }
}

Response

Webhook received successfully