Webhook events
A node sends an event to each matching webhook subscription after the change it describes has been committed. Subscribe to all events, or filter with --events.
The envelope
Section titled “The envelope”Every delivery’s body is the same versioned envelope:
{ "version": 1, "eventId": "01964f3a-…", "eventType": "dpp.passport.published", "timestamp": "2026-05-27T14:30:00Z", "operatorId": "self_hosted", "data": { "passportId": "…", "status": "active" }}eventIdis a time-ordered UUID (v7): use it to ignore a delivery you have already processed.versionchanges only if the shape ofdatachanges in a breaking way.- The event type is also sent in the
X-Odal-Eventheader, and the signature inX-Odal-Signature.
Event types
Section titled “Event types”| Event | When it is sent |
|---|---|
dpp.passport.created |
A draft passport was created |
dpp.passport.updated |
A draft passport was changed |
dpp.passport.published |
A passport was signed and published |
dpp.passport.suspended |
A published passport was suspended |
dpp.passport.superseded |
A passport was replaced by a successor; data carries successorId, and the superseded record stays resolvable |
dpp.passport.retired |
A passport was retired |
dpp.passport.deactivated |
A passport’s end of life was declared |
dpp.passport.transferred |
A handover of responsibility changed state |
odal webhook test <id> sends a test delivery with its own event type, so you can check your receiver without changing a passport.
Verifying a delivery
Section titled “Verifying a delivery”X-Odal-Signature: t=<unix-time>,v1=<hex HMAC-SHA256(secret, "<t>.<body>")>- Split the header into the timestamp
tand the signaturev1. - Compute HMAC-SHA256 over
"<t>.<raw body>"with your subscription’s secret. - Compare with
v1in constant time. - Reject a timestamp older than a few minutes, and an
eventIdyou have seen before.
A delivery that fails is retried with backoff, up to eight attempts in all.
Read next
Section titled “Read next”- Integrations and statistics: adding and testing subscriptions.
- Error reference: what the API returns when a call fails.
Information on this site is not legal advice. Legal noticePrivacy policy