Skip to main content
WEBHOOK

Authorizations

X-Meridian-Signature
string
header
required

Meridian signs every webhook it sends you.

Headers on every delivery:

  • X-Meridian-Api-Key
  • X-Meridian-Timestamp
  • X-Meridian-Signature

X-Meridian-Signature is the lowercase hex HMAC-SHA256 of apiKey + timestamp + "POST" + path + body, keyed with your webhook secret. The path is the path of your webhook URL, without any query string. The body is the raw request body, byte for byte. Recompute the signature and reject the request if it does not match. See Security.

Headers

X-Meridian-Resource-Type
string
required

The resource this event is about. Always account for this webhook.

Allowed value: "account"
X-Meridian-Event-Type
enum<string>
required

Which event fired. account_created when the account is created, account_status_updated after it changes.

Available options:
account_created,
account_status_updated
X-Meridian-Api-Key
string
required

Your webhook API key. Meridian issues it separately from your REST API credentials, and uses one key for every webhook event. Use it to choose the webhook secret to verify with. The key on its own does not prove the request came from Meridian; the signature does.

X-Meridian-Timestamp
string
required

When Meridian signed this delivery attempt, in milliseconds since the Unix epoch. Every retry is signed again, so each attempt has a new timestamp. Reject requests whose timestamp is far from your own clock.

Pattern: ^[0-9]+$

Body

application/json
account
Account · object
required

A main balance account. This is a smaller set of fields than the List accounts response: balances, rails, and network are not sent. Call GET /v1/accounts/{accountId} for those. Fields with no value are left out rather than sent as null.

metadata
Webhook Metadata · object
required

Identifies the user and program the event belongs to.

Response

200

Return any 2xx status within 10 seconds to acknowledge the webhook.