After the user passes the identity verification flow successfully, the system can notify you with the result details via your registered webhook.
On finish of the IDV flow, the system makes a POST request to your webhook with the results details in the request body represented as a MIME message where images are in separate parts.
To secure requests, the system sets the
X-CLIENT-IDheader to your
Client IDand the
X-SIGNATUREone to the hex-encoded SHA256 digest of the request body and your
To accept requests, please do the following:
- 1.Compare the
X-CLIENT-IDheader with your
- 2.Access the request body before it's parsed
- 3.Calculate the SHA 256 digest of the request body and your
- 4.Compare the hex-encoded digest with the
- 5.Parse and handle the request body if they are identical
- 6.Response with the
When your webhook is not accessible or responses with the status code that is not
200, the system retries an attempt in an hour and repeat attempts for a week, so you have time to fix issues on your side.
Below is an example specification of such webhook endpoint.
Webhook Endpoint Example