{
"informationRequest": {
"id": "usrsk-iustro3s1opjhgosud9k0i4g",
"status": "PROCESSING_SUBMISSION",
"subjectType": "ENROLLMENT",
"subjectId": "usrem-gn3avwnd81gfy0fmmottcs39",
"validationStatus": "VALID",
"decision": null,
"createdAt": "2026-09-22T09:00:00.000Z",
"updatedAt": "2026-09-23T11:30:00.000Z"
},
"metadata": {
"userId": "ususr-c2yulm8b8phkkjpbzra2s263",
"programId": "usrem-bvjxs5xuca4oa093pax3p6p2"
}
}Information Request
Learn when Information Request webhooks are sent and what data they include.
{
"informationRequest": {
"id": "usrsk-iustro3s1opjhgosud9k0i4g",
"status": "PROCESSING_SUBMISSION",
"subjectType": "ENROLLMENT",
"subjectId": "usrem-gn3avwnd81gfy0fmmottcs39",
"validationStatus": "VALID",
"decision": null,
"createdAt": "2026-09-22T09:00:00.000Z",
"updatedAt": "2026-09-23T11:30:00.000Z"
},
"metadata": {
"userId": "ususr-c2yulm8b8phkkjpbzra2s263",
"programId": "usrem-bvjxs5xuca4oa093pax3p6p2"
}
}Authorizations
Meridian signs every webhook it sends you.
Headers on every delivery:
- X-Meridian-Api-Key
- X-Meridian-Timestamp
- X-Meridian-Signature
X-Meridian-Signature is the lowercase hex HMAC-SHA256 of apiKey + timestamp + "POST" + path + body, keyed with your webhook secret. The path is the path of your webhook URL, without any query string. The body is the raw request body, byte for byte. Recompute the signature and reject the request if it does not match. See Security.
Headers
The resource this event is about. Always information_request for this webhook.
"information_request"Which event fired. Always information_request_status_updated.
information_request_status_updated Your webhook API key. Meridian issues it separately from your REST API credentials, and uses one key for every webhook event. Use it to choose the webhook secret to verify with. The key on its own does not prove the request came from Meridian; the signature does.
When Meridian signed this delivery attempt, in milliseconds since the Unix epoch. Every retry is signed again, so each attempt has a new timestamp. Reject requests whose timestamp is far from your own clock.
^[0-9]+$Body
Response
Return any 2xx status within 10 seconds to acknowledge the webhook.