kyc.rejected
Business verification was rejected. note says why.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Header Parameters
Section titled “Header Parameters”The event ID (evt_…); the same on every retry. Deduplicate on it.
Example
evt_3fT9kq2ZpLr8YwVbN1cX0aUnix seconds of this delivery attempt. Reject deliveries more than 5 minutes old.
Example
1762161262Space-separated v1,<base64 HMAC-SHA256> signatures of <webhook-id>.<webhook-timestamp>.<body> with the endpoint secret (two while a secret rotates).
Example
v1,K5oZfzN95Z9UVu1EsfQmfVNQhnkZ2pj9o9NDN/H/pI4=Request Bodyrequired
Section titled “Request Bodyrequired”Business verification was rejected. note says why.
object
The API version the payload is rendered in (the endpoint’s pinned version).
An ISO-8601 timestamp in UTC.
object is the object the kyc.rejected event is about.
object
object
The reviewer’s note to the organisation (rejections, information requests).
For *.updated-style events: the changed attributes’ previous values.
object
The event ID. Receivers deduplicate on it (it is also the webhook-id header).
true in live mode, false in test mode.
The organisation the event belongs to.
Example
{ "api_version": "2026-11-01", "created": "2026-11-03T09:14:22.000Z", "data": { "object": { "id": "kyc_UhYXwh1cUMNBIX6yxg4O2D", "note": "…", "object": "outbound_kyc", "previous_status": "…", "status": "…" } }, "id": "evt_3fT9kq2ZpLr8YwVbN1cX0a", "livemode": true, "object": "event", "org_id": "org_0000000000000000000001", "request": { "id": null, "idempotency_key": null }, "type": "kyc.rejected"}Responses
Section titled “Responses”Acknowledge the event with any 2xx status within 15 seconds. Anything else, or a timeout, is retried for up to 72 hours.