Webhook Verification Key

webhookVerificationKeyGet

POST
/webhook_verification_key/get

Plaid signs all outgoing webhooks and provides JSON Web Tokens (JWTs) so that you can verify the authenticity of any incoming webhooks to your application. A message signature is included in the Plaid-Verification header.

The /webhook_verification_key/get endpoint provides a JSON Web Key (JWK) that can be used to verify a JWT.

Authorization

PLAID-CLIENT-ID PLAID-SECRET Plaid-Version
PLAID-CLIENT-ID<token>

In: header

PLAID-SECRET<token>

In: header

Plaid-Version<token>

In: header

Request Body

application/json

WebhookVerificationKeyGetRequest defines the request schema for /webhook_verification_key/get

client_id?string

Your Plaid API client_id. The client_id is required and may be provided either in the PLAID-CLIENT-ID header or as part of a request body.

secret?string

Your Plaid API secret. The secret is required and may be provided either in the PLAID-SECRET header or as part of a request body.

key_id*string

The key ID ( kid ) from the JWT header.

Response Body

application/json

curl -X POST "https://example.com/webhook_verification_key/get" \  -H "Content-Type: application/json" \  -d '{    "key_id": "string"  }'
{  "key": {    "alg": "ES256",    "created_at": 1560466150,    "crv": "P-256",    "expired_at": null,    "kid": "bfbd5111-8e33-4643-8ced-b2e642a72f3c",    "kty": "EC",    "use": "sig",    "x": "hKXLGIjWvCBv-cP5euCTxl8g9GLG9zHo_3pO5NN1DwQ",    "y": "shhexqPB7YffGn6fR6h2UhTSuCtPmfzQJ6ENVIoO4Ys"  },  "request_id": "RZ6Omi1bzzwDaLo"}