Session and submission event
Steve POSTs this to the session's `webhookUrl` when a session completes, fails, needs review or expires, and after each submission action (approve, reject, cancel, fraud resolution). The body is fixed when the event is created: every retry of one `X-Webhook-Id` sends identical bytes. Verify `X-Webhook-Signature` against the raw body before parsing it.
Authorization
AuthorizationRequiredBearer <token>Steve API key, usually scoped to a company. Legacy keys and keys created by platform administrators may be unscoped; company-scoped endpoints reject unscoped keys with 403 Forbidden. Format: Authorization: Bearer aok_...
In: header
Request Body
application/jsonRequiredeventIdRequiredstringeventTypeRequiredstring"session.completed" | "session.failed" | "session.review_required" | "session.expired" | "submission.approved" | "submission.rejected" | "submission.cancelled" | "submission.fraud_match_resolved"occurredAtRequiredstring | null"date-time"sessionIdRequiredstringsubmissionIdRequiredstring | nullworkflowRequiredobjectstateRequiredstringsubmissionStatusRequiredstringcompanyIdRequiredstringresultRequiredunknownA SubmissionResult (see that schema), including matchedItems, fixed when the event was created: every retry of one eventId sends identical bytes.
failedReasonRequiredstring | nullclientSubmissionIdRequiredstring | nullmetadataRequiredunknownprocessedAtRequiredstring | null"date-time"Header Parameters
X-Webhook-SignatureRequiredstringsha256= followed by the lowercase hex HMAC-SHA256 of the raw request body. The HMAC key is the API key's SHA-256 digest rendered as lowercase hex.
"^sha256=[0-9a-f]{64}$"X-Webhook-EventRequiredstringThe event type, equal to the type carried in the body.
X-Webhook-IdRequiredstringEvent ID, unchanged across retries of the same event. Deduplicate deliveries by this value.
X-Webhook-TimestampRequiredstringUnix seconds when this delivery attempt was sent. Changes on every retry.
"^[0-9]+$"User-AgentRequiredstringSender identifier.