Webhooks
Signed deliveries when a monitored status changes, and how to verify the signature.
When you configure a webhook endpoint, Exclia pushes signed deliveries for three events:
match_status_change (a monitored entity’s screening status changed), batch_completed, and
list_update. Screening payloads carry only clear or potential_match with per-field evidence
and provenance (list_version ids and retrieval dates) — never an automated “excluded” verdict.
Each delivery is a JSON body with headers Exclia-Webhook-Id (the delivery id), Exclia-Event-Type,
and Exclia-Signature: t=<unixSeconds>,v1=<hex>.
Verifying a delivery
- Read
tandv1from theExclia-Signatureheader. - Reject the delivery if
tis more than 5 minutes from your current time (replay protection). - Compute
HMAC-SHA256(signingSecret, "<t>." + rawRequestBody)as lowercase hex — use the EXACT received bytes, before any JSON re-serialization. - Constant-time compare your hex digest to
v1. If they differ, the payload was tampered with or signed with a different secret — discard it. Only on a match do you trust the event. - Respond
2xxto acknowledge. A non-2xx or timeout is retried with exponential backoff; every attempt is recorded in your delivery log, and you can replay any delivery from it.
Your signing secret is shown once when you register or rotate the endpoint. Rotate it if it leaks; the previous secret stops signing immediately.
