IDCanopy Developers
Hosted Verification Journeys (SDK)

Webhooks

Journey event delivery, signature verification, and the payload shape

Pending verification: this page's guidance has not been re-checked against the live webhook sender.

Delivery

  • HTTPS endpoint, POST, JSON body
  • Return HTTP 2xx within 10 seconds
  • Retries for approximately 24 hours: up to 6 additional attempts with increasing backoff

Signature

Each request carries a Signature header: an HMAC-SHA256 of the raw request body, keyed with your webhook secret. Verify it with a constant-time comparison.

Payload

Journey webhook payloads include transactionId, customerId, timestamp, status, journeySummary.identitySubject, journeySummary.authoritativeData, journeySummary.journeyStats, and your original passThroughData. Field-level detail is "pending" until re-verified against a live payload.

See also Guides / Webhooks for the cross-service overview.

On this page