# Verification Completed

Delivered when a verification session reaches a terminal status (`success`, `failed`, or `expired`).
Fetch the full session snapshot — requested fields, captured `credential_subject_data`, error fields — via `GET /b2b/v1/verification-sessions/{sessionId}`.

Endpoint: POST verification.completed
Version: 1.2.0

## Header parameters:

  - `X-Webhook-Event` (string, required)
    Event type (same as `event` field in body).

  - `X-Webhook-Signature` (string, required)
    HMAC-SHA256 hex digest of the raw request body. Verifying is **recommended** — see the [Webhooks guide](../guides/webhooks.md#verifying-signatures).

  - `X-Webhook-Timestamp` (string, required)
    Unix timestamp of the event.

  - `X-Webhook-Signature-Previous` (string)
    Present during the 24-hour secret rotation grace period — signature with the previous secret.

## Request fields (application/json):

  - `event` (string, required)
    Event type identifier (same value as the `X-Webhook-Event` header).

  - `tenant_id` (string, required)
    Your organization ID.
    Example: 550e8400-e29b-41d4-a716-446655440000

  - `timestamp` (string, required)
    When the event occurred (RFC 3339 UTC).
    Example: 2026-05-16T10:00:00Z

  - `data` (object, required)

  - `data.session_id` (string, required)
    ID of the verification session. Fetch the full snapshot (requested fields, captured `credential_subject_data`, error fields) via `GET /b2b/v1/verification-sessions/{sessionId}`.
    Example: 7c9e6679-7425-40de-944b-e07fc1f90ae7

  - `data.status` (string, required)
    Terminal status reached.
    Enum: "success", "failed", "expired"

  - `data.credential_status` (string)
    Token-status-list state of the presented credential. Present when a successful verification resolved credential status; evaluate it in addition to `status` when suspended or revoked credentials should not be accepted.
    Enum: "valid", "suspended", "revoked"

