External account webhook
Webhook that is called whenever the status or the account details of an external account change. Status changes cover any transition between statuses (PENDING, ACTIVE, UNDER_REVIEW, INACTIVE, PENDING_OWNERSHIP_VERIFICATION, UNVERIFIED) — for example when an account under review becomes active, when ownership verification completes (PENDING_OWNERSHIP_VERIFICATION → ACTIVE), or when a verification attempt fails (PENDING_OWNERSHIP_VERIFICATION → UNVERIFIED).
This endpoint should be implemented by clients of the Grid API.
Authentication
The webhook includes a signature in the X-Grid-Signature header that allows you to verify that the webhook was sent by Grid.
To verify the signature:
- Get the Grid public key provided to you during integration
- Decode the base64 signature from the header
- Create a SHA-256 hash of the request body
- Verify the signature using the public key and the hash
If the signature verification succeeds, the webhook is authentic. If not, it should be rejected.
Event types
EXTERNAL_ACCOUNT.STATUS_UPDATED— Fired when the status of an external account changes. Thedatapayload contains the full external account object.EXTERNAL_ACCOUNT.ACCOUNT_INFO_UPDATED— Fired when Grid corrects an external account’saccountInfo. Today this happens when the receiving bank sends an ACH notification of change (NOC) with corrected details, such as a new routing number, account number or bank account type. The account keeps itsid, and later payments to it use the corrected details. Thedatapayload contains the full external account object with the correctedaccountInfo. Deliveries can arrive out of order, and the external account has no version field, so an olderSTATUS_UPDATEDpayload can carry the pre-correction details. Before you replace a stored copy of the account details, fetch the current account withGET /customers/external-accounts/{externalAccountId}(or the platform equivalent) and store that response.
Authorizations
Secp256r1 (P-256) asymmetric signature of the webhook payload, which can be used to verify that the webhook was sent by Grid. To verify the signature:
- Get the Grid public key provided to you during integration
- Decode the base64 signature from the header
- Create a SHA-256 hash of the request body
- Verify the signature using the public key and the hash
If the signature verification succeeds, the webhook is authentic. If not, it should be rejected.
Body
Unique identifier for this webhook delivery (can be used for idempotency)
"Webhook:019542f5-b3e7-1d02-0000-000000000007"
Status-specific event type in OBJECT.EVENT dot-notation (e.g., OUTGOING_PAYMENT.COMPLETED)
EXTERNAL_ACCOUNT.STATUS_UPDATED, EXTERNAL_ACCOUNT.ACCOUNT_INFO_UPDATED ISO 8601 timestamp of when the webhook was sent
"2025-08-15T14:32:00Z"
Response
Webhook received successfully