Every request includes an HMAC-SHA256 signature in the Signatureheader. Verify it before processing — see Webhook Security.
kyb.status_updated| Header | Value |
|---|---|
Content-Type | application/json |
Event | kyb.status_updated |
Signature | HMAC-SHA256 of the body. |
| Field | Type | Description |
|---|---|---|
event | String | Always kyb.status_updated. |
timestamp | String | Event time in ISO 8601 format (e.g., 2026-05-11T09:15:00+07:00). |
data.merchant_id | UUID | The merchant's unique identifier. |
data.onboarding_status | String | The new KYB status. |
data.rejected_entities | Array|absent | Present when status is kyb_rejected or kyb_revision_needed. |
rejected_entities Object| Field | Type | Description |
|---|---|---|
type | String | The entity type that failed verification (e.g., BUSINESS, OWNER, BRAND). |
reason | String | Human-readable rejection reason. |
merchant.activatedonboarding_status: active). Loan submission is permitted after receiving this event.| Header | Value |
|---|---|
Content-Type | application/json |
Event | merchant.activated |
Signature | HMAC-SHA256 of the body. |
| Field | Type | Description |
|---|---|---|
event | String | Always merchant.activated. |
timestamp | String | Event time in ISO 8601 format (e.g., 2026-05-11T09:30:00+07:00). |
data.merchant_id | UUID | The merchant's unique identifier. |
data.onboarding_status | String | Value: active. |
data.qris_code | String|null | Assigned QRIS payload / NMID string for the merchant. |