Skip to main content

Bind a webhook to an auth profile

POST 

/v1/webhooks/:webhook_id/bind

Bind a webhook subscription to an OAuth2 receiver auth profile, so that every delivery to this subscription carries an access token from your own token endpoint. Requires the connector:auth-profiles:bind scope and an Idempotency-Key header.

Send data.type: webhooks and the auth_profile_id (a UUID) of a profile created with POST /v1/auth-profiles. Both the webhook and the auth profile must belong to the calling bank; otherwise the request fails with 400 and nothing changes. Binding again with a different auth_profile_id replaces the previous binding. There is currently no unbind request.

Effect. Once bound, before each delivery the platform obtains an access token from the profile's token endpoint with the OAuth2 client credentials grant (see POST /v1/auth-profiles) and sends it as Authorization: Bearer <token>, in addition to the HMAC signature. Binding also moves the subscription back to PENDING_VERIFICATION and sends a new webhook.verification event (with the bearer token). Business events are not delivered until your endpoint answers that event with a 2xx status and the subscription is ACTIVE again.

Request​

Responses​

Accepted. The binding is applied and the subscription is in PENDING_VERIFICATION until the new verification handshake succeeds.