# Credential Status Changed

Delivered when an issued credential's status changes (`revoked`, `suspended`, or `active` for a reactivation).
Fetch the full credential snapshot via `GET /b2b/v1/issued-credentials/{credentialId}`.

Endpoint: POST credential.status_changed
Version: 1.2.0

## Header parameters:

  - `X-Webhook-Event` (string, required)
    Event type (same as `event` field in body).

  - `X-Webhook-Signature` (string, required)
    HMAC-SHA256 hex digest of the raw request body. Verifying is **recommended** — see the [Webhooks guide](../guides/webhooks.md#verifying-signatures).

  - `X-Webhook-Timestamp` (string, required)
    Unix timestamp of the event.

  - `X-Webhook-Signature-Previous` (string)
    Present during the 24-hour secret rotation grace period — signature with the previous secret.

## Request fields (application/json):

  - `event` (string, required)
    Event type identifier (same value as the `X-Webhook-Event` header).

  - `tenant_id` (string, required)
    Your organization ID.
    Example: 550e8400-e29b-41d4-a716-446655440000

  - `timestamp` (string, required)
    When the event occurred (RFC 3339 UTC).
    Example: 2026-05-16T10:00:00Z

  - `data` (object, required)

  - `data.credential_id` (string, required)
    ID of the issued credential. Fetch the full snapshot via `GET /b2b/v1/issued-credentials/{credentialId}`.
    Example: 7c9e6679-7425-40de-944b-e07fc1f90ae7

  - `data.status` (string, required)
    New credential status.
    Enum: "active", "suspended", "revoked"

