The Webhook Event Object

KeyTypeDescription
event_idStringA unique identifier for the event object.
closing_uuidStringThe internal unique identifier for a Snapdocs closing.
event_nameStringThe name of the event being broadcast via the webhook.
created_atIntegerThe Unix timestamp for when the event was generated.
payloadObjectAn object containing additional information of the event.
external_identifiersObjectA map of external_identifiers to correlate those identifiers to the event.
{
	"event_id": "572f592a-fbec-49d9-a28a-88d8e38175be",
	"closing_uuid": "d679e2ad-278d-e547-9756-84639ba3865b",
	"event_name": "borrower.preview_available",
	"created_at": 1618936005,
	"payload": {
		"external_identifiers": [{
			"external_system": "other_los",
			"external_type": "file_number",
			"value": "1234"
		}]
	}
}

How can we verify a webhook's integrity and authenticity?

Every webhook is signed with a hash-based message authentication code (HMAC) carried in three X-Authorization-* headers. The HMAC key is returned in the body of the response when a subscription is created, and is also available from the Get Subscriptions endpoint. Verification steps and code samples in four languages are on Webhook security.

Should we send a response after receiving a webhook, and in what format?

Respond with HTTP 200 to indicate the webhook was received; use an appropriate error status otherwise.

HTTP/1.1 200 OK
Content-Type: application/json

{
	"status": "OK",
	"code": 200,
	"message": "webhook received successfully"
}