Account
Learn when account webhooks are sent and what data they include.
Authorizations
Meridian signs every webhook it sends you.
Headers on every delivery:
- X-Meridian-Api-Key
- X-Meridian-Timestamp
- X-Meridian-Signature
X-Meridian-Signature is the lowercase hex HMAC-SHA256 of apiKey + timestamp + "POST" + path + body, keyed with your webhook secret. The path is the path of your webhook URL, without any query string. The body is the raw request body, byte for byte. Recompute the signature and reject the request if it does not match. See Security.
Headers
The resource this event is about. Always account for this webhook.
"account"Which event fired. account_created when the account is created, account_status_updated after it changes.
account_created, account_status_updated Your webhook API key. Meridian issues it separately from your REST API credentials, and uses one key for every webhook event. Use it to choose the webhook secret to verify with. The key on its own does not prove the request came from Meridian; the signature does.
When Meridian signed this delivery attempt, in milliseconds since the Unix epoch. Every retry is signed again, so each attempt has a new timestamp. Reject requests whose timestamp is far from your own clock.
^[0-9]+$Body
A main balance account. This is a smaller set of fields than the List accounts response: balances, rails, and network are not sent. Call GET /v1/accounts/{accountId} for those. Fields with no value are left out rather than sent as null.
Show child attributes
Show child attributes
Identifies the user and program the event belongs to.
Show child attributes
Show child attributes
Response
Return any 2xx status within 10 seconds to acknowledge the webhook.