QFAST API Documentation
  1. Webhook
  • Introduction
  • Authentication
  • Onboarding Flow
  • Loan Flow
  • Disbursement Flow
  • Repayment Flow
  • Area Reference
  • API
    • Obtain an Access Token
      POST
    • Onboarding Personal
      POST
    • Get Onboarding Status
      GET
    • Submit Loan
      POST
    • Update Loan
      PATCH
    • Get Loan
      GET
  • Webhook
    • Onboarding Webhooks
    • Loan Webhooks
    • Disbursement Webhooks
    • Repayment Webhooks
  1. Webhook

Onboarding Webhooks

QFAST sends asynchronous webhook notifications to your configured endpoint when KYB status changes. Configure your webhook URL via QFAST's lender settings.
Every request includes an HMAC-SHA256 signature in the Signature header. Verify it before processing — see Webhook Security.

Event: kyb.status_updated#

Fired whenever the merchant's KYB status changes. This covers all intermediate and terminal states.

Headers#

HeaderValue
Content-Typeapplication/json
Eventkyb.status_updated
SignatureHMAC-SHA256 of the body.

Payload Structure#

FieldTypeDescription
eventStringAlways kyb.status_updated.
timestampStringEvent time in ISO 8601 format (e.g., 2026-05-11T09:15:00+07:00).
data.merchant_idUUIDThe merchant's unique identifier.
data.onboarding_statusStringThe new KYB status.
data.rejected_entitiesArray|absentPresent when status is kyb_rejected or kyb_revision_needed.

rejected_entities Object#

FieldTypeDescription
typeStringThe entity type that failed verification (e.g., BUSINESS, OWNER, BRAND).
reasonStringHuman-readable rejection reason.

Example: KYB Approved#

Example: KYB Revision Needed#


Event: merchant.activated#

Fired when internal wallet and account linking complete and the merchant reaches fully active status (onboarding_status: active). Loan submission is permitted after receiving this event.

Headers#

HeaderValue
Content-Typeapplication/json
Eventmerchant.activated
SignatureHMAC-SHA256 of the body.

Payload Structure#

FieldTypeDescription
eventStringAlways merchant.activated.
timestampStringEvent time in ISO 8601 format (e.g., 2026-05-11T09:30:00+07:00).
data.merchant_idUUIDThe merchant's unique identifier.
data.onboarding_statusStringValue: active.
data.qris_codeString|nullAssigned QRIS payload / NMID string for the merchant.

Example: Merchant Activated#

Previous
Get Loan
Next
Loan Webhooks
Built with