Skip to main content
POST
Create a webhook subscription

Authorizations

X-API-Key
string
header
required

Your workspace public key (pk_test_… or pk_live_…).

X-HMAC-Signature
string
header
required

HMAC-SHA256 of the request, hex-encoded, keyed with the workspace secret key. See API authentication.

Body

application/json
url
string<uri>
required

Where ProofAge POSTs the decision webhooks, signed like the workspace webhook. It must be a public URL: private, local and cloud-metadata addresses are refused.

Maximum string length: 2048
include_document_data
boolean
default:false

Include the document read from the identity document (names, date of birth, document number), the fingerprint signals (IP address, timezones) and the name and email of the operator who moderated. Off by default, so personal data stays out of the subscriber's logs.

statuses
enum<string>[] | null

Only send these statuses: approved, declined, resubmission_requested, review, abandoned, expired. Omit it, or send null, for all of them.

Available options:
approved,
declined,
resubmission_requested,
abandoned,
expired,
review

Response

The subscription. statuses is null when it receives every decision status.

id
string
required
url
string
required
statuses
string[] | null
required
include_document_data
boolean
required
created_at
string
required