SteveSteve

Session and submission event

Steve POSTs this to the session's `webhookUrl` when a session completes, fails, needs review or expires, and after each submission action (approve, reject, cancel, fraud resolution). The body is fixed when the event is created: every retry of one `X-Webhook-Id` sends identical bytes. Verify `X-Webhook-Signature` against the raw body before parsing it.

Authorization

AuthorizationRequiredBearer <token>

Steve API key, usually scoped to a company. Legacy keys and keys created by platform administrators may be unscoped; company-scoped endpoints reject unscoped keys with 403 Forbidden. Format: Authorization: Bearer aok_...

In: header

Request Body

application/jsonRequired
eventIdRequiredstring
eventTypeRequiredstring
Value in: "session.completed" | "session.failed" | "session.review_required" | "session.expired" | "submission.approved" | "submission.rejected" | "submission.cancelled" | "submission.fraud_match_resolved"
occurredAtRequiredstring | null
Format: "date-time"
sessionIdRequiredstring
submissionIdRequiredstring | null
workflowRequiredobject
stateRequiredstring
submissionStatusRequiredstring
companyIdRequiredstring
resultRequiredunknown

A SubmissionResult (see that schema), including matchedItems, fixed when the event was created: every retry of one eventId sends identical bytes.

failedReasonRequiredstring | null
clientSubmissionIdRequiredstring | null
metadataRequiredunknown
processedAtRequiredstring | null
Format: "date-time"

Header Parameters

X-Webhook-SignatureRequiredstring

sha256= followed by the lowercase hex HMAC-SHA256 of the raw request body. The HMAC key is the API key's SHA-256 digest rendered as lowercase hex.

Pattern: "^sha256=[0-9a-f]{64}$"
X-Webhook-EventRequiredstring

The event type, equal to the type carried in the body.

X-Webhook-IdRequiredstring

Event ID, unchanged across retries of the same event. Deduplicate deliveries by this value.

X-Webhook-TimestampRequiredstring

Unix seconds when this delivery attempt was sent. Changes on every retry.

Pattern: "^[0-9]+$"
User-AgentRequiredstring

Sender identifier.