Skip to main content
WEBHOOK

Authorizations

X-Meridian-Signature
string
header
required

Meridian signs every webhook it sends you.

Headers on every delivery:

  • X-Meridian-Api-Key
  • X-Meridian-Timestamp
  • X-Meridian-Signature

X-Meridian-Signature is the lowercase hex HMAC-SHA256 of apiKey + timestamp + "POST" + path + body, keyed with your webhook secret. The path is the path of your webhook URL, without any query string. The body is the raw request body, byte for byte. Recompute the signature and reject the request if it does not match. See Security.

Headers

X-Meridian-Resource-Type
string
required

The resource this event is about. Always information_request for this webhook.

Allowed value: "information_request"
X-Meridian-Event-Type
enum<string>
required

Which event fired. Always information_request_status_updated.

Available options:
information_request_status_updated
X-Meridian-Api-Key
string
required

Your webhook API key. Meridian issues it separately from your REST API credentials, and uses one key for every webhook event. Use it to choose the webhook secret to verify with. The key on its own does not prove the request came from Meridian; the signature does.

X-Meridian-Timestamp
string
required

When Meridian signed this delivery attempt, in milliseconds since the Unix epoch. Every retry is signed again, so each attempt has a new timestamp. Reject requests whose timestamp is far from your own clock.

Pattern: ^[0-9]+$

Body

application/json
informationRequest
Information Request · object
required

An Information Request. Every key is always present. Fields with no value are sent as null.

metadata
Webhook Metadata · object
required

Identifies the user and program the event belongs to.

Response

200

Return any 2xx status within 10 seconds to acknowledge the webhook.