Configure webhook delivery for an onboarding case
PUT/v1/onboarding-cases/:case_id/webhook-setup
Saves the webhook subscription the platform creates for your bank when onboarding is
activated. Webhook delivery is required: the platform must be able to send you
beneficiary.screening.requested events, so a case cannot be submitted without a
complete webhook setup (readiness.webhook_ready).
Required scope: connector:onboarding:artifacts:write.
Allowed states: AWAITING_BANK_ADMIN, BANK_CONFIGURING, NEEDS_CHANGES
(otherwise 409). The first edit moves AWAITING_BANK_ADMIN to BANK_CONFIGURING.
Each call replaces the whole setup. No Idempotency-Key is used; repeating a request
has the same effect.
Fields (all in data.attributes):
enabled(required): must betrue;falsereturns400.url(required): absolutehttpsURL with a host that receives the callbacks. Returned ascallback_url.event_types(required, at least one, unique): must includebeneficiary.screening.requested.delivery_format(optional, defaultjsonapi): onlyjsonapiis accepted.signing_secret(write-only): the shared secret used to sign each delivery so you can verify it. Must not be blank. The setup is incomplete until a secret has been supplied once; when omitted on a later call, the secret saved earlier is kept.signing_secret_version(optional, defaultv1): label for the signing secret; 1 to 64 printable ASCII characters without spaces.receiver_auth(optional): set it if your endpoint requires an OAuth 2.0 client-credentials access token.token_endpoint_url(absolutehttpsURL),client_idandrequested_scopeare required and must not be blank;client_secret(write-only) must be supplied once for the setup to be complete and is kept when omitted later. Omittingreceiver_authremoves receiver authentication and discards any saved client secret.
Secrets. Secrets are stored encrypted by the platform and are never returned.
The case shows only signing_secret_configured and
receiver_auth.client_secret_configured.
Validation order. Field format rules (enabled, url, event_types,
delivery_format, blank secrets) are checked before authorisation and return 400
with a source.pointer. The secret-version format is checked afterwards and returns
422.
The response is the updated case; the saved setup is in
data.attributes.configuration.webhook_setup.
Request
Responses
- 200
- 400
- 401
- 403
- 404
- 409
- 422
- 503
The webhook setup was saved. Returns the updated case, including readiness.
A field failed a format rule. source.pointer names the field.
The bearer token is missing, malformed, expired, signed by an unknown key, or was not issued by the platform IAM for the Lyriq Connector. Obtain a new token and retry. See the Authentication section.
The token is valid but may not perform this request: it lacks the required scope, has
no bank membership, needs an x-dan-bank-id header to choose between several
memberships, names a bank in x-dan-bank-id it has no membership for, or the caller's
bank is suspended or terminated. A new token with the same configuration fails the same
way. See the Authentication section.
The resource does not exist, or it belongs to another bank. The Lyriq Connector does not distinguish the two cases, so resources of other banks are never disclosed.
The request conflicts with an earlier request or with the current state of the target:
an Idempotency-Key reused with a different body (IDEMPOTENCY_CONFLICT), a request with
the same key still in progress (IDEMPOTENCY_PENDING), or a target resource in a state
that does not allow the request (STATE_CONFLICT).
The request is well-formed JSON but cannot be processed: the body does not match the
expected shape (a missing or unknown member, a wrong type, or a wrong data.type), or it
breaks a business or cross-field rule. Correct the request before retrying.
The request could not be served right now. Either the network is not fully operational
(OUTBOUND_HALTED or READ_ONLY: mutations are refused while read endpoints keep
working; OPERATIONAL_STATE_UNKNOWN: the state could not be determined), or a platform
dependency is temporarily unavailable. No Retry-After header is sent; retry later with
backoff. When retrying a mutation, reuse the same Idempotency-Key and body.