---
title: "Get webhook verification key"
method: POST
path: "/webhook_verification_key/get"
tags: ["plaid"]
---

# Get webhook verification key

`POST /webhook_verification_key/get`

Plaid signs all outgoing webhooks and provides JSON Web Tokens (JWTs) so that you can verify the authenticity of any incoming webhooks to your application. A message signature is included in the `Plaid-Verification` header.

The `/webhook_verification_key/get` endpoint provides a JSON Web Key (JWK) that can be used to verify a JWT.

## Request body

- WebhookVerificationKeyGetRequest — WebhookVerificationKeyGetRequest defines the request schema for `/webhook_verification_key/get`
  - `client_id` string — Your Plaid API `client_id`. The `client_id` is required and may be provided either in the `PLAID-CLIENT-ID` header or as part of a request body.
  - `secret` string — Your Plaid API `secret`. The `secret` is required and may be provided either in the `PLAID-SECRET` header or as part of a request body.
  - `key_id` string, required — The key ID ( `kid` ) from the JWT header.

## Response `200`

OK

- WebhookVerificationKeyGetResponse — WebhookVerificationKeyGetResponse defines the response schema for `/webhook_verification_key/get`
  - `key` JWKPublicKey, required — A JSON Web Key (JWK) that can be used in conjunction with [JWT libraries](https://jwt.io/#libraries-io) to verify Plaid webhooks
    - `alg` string, required — The alg member identifies the cryptographic algorithm family used with the key.
    - `crv` string, required — The crv member identifies the cryptographic curve used with the key.
    - `kid` string, required — The kid (Key ID) member can be used to match a specific key. This can be used, for instance, to choose among a set of keys within the JWK during key rollover.
    - `kty` string, required — The kty (key type) parameter identifies the cryptographic algorithm family used with the key, such as RSA or EC.
    - `use` string, required — The use (public key use) parameter identifies the intended use of the public key.
    - `x` string, required — The x member contains the x coordinate for the elliptic curve point, provided as a base64url-encoded string of the coordinate's big endian representation.
    - `y` string, required — The y member contains the y coordinate for the elliptic curve point, provided as a base64url-encoded string of the coordinate's big endian representation.
    - `created_at` integer, required — The timestamp when the key was created, in Unix time.
    - `expired_at` integer, nullable, required — The timestamp when the key expired, in Unix time.
  - `request_id` string, required — A unique identifier for the request, which can be used for troubleshooting. This identifier, like all Plaid identifiers, is case sensitive.

## Other responses

- `default` — Error response

---

[API](https://skmtc.net/plaid/apis/the-plaid-api.md) · [All operations](https://skmtc.net/plaid/apis/the-plaid-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/plaid/the-plaid-api/revisions/64c4514ea59b/schema)
