Use browser status for UX. Use webhooks and signed results for backend state changes. Authbound delivers webhook events at least once and retries failed deliveries with exponential backoff.

Verify webhook signatures

Webhook events include api_version and contract_revision alongside the event type. Use contract_revision when a consumer pins or audits the payload contract.

Fetch a signed result

Common events

Failed verification objects carry a failure_code (for example user_declined, policy_not_satisfied, wallet_error). Non-failed objects do not include one. See verification overview for the full list.

Retry handling

Webhook handlers should be idempotent. Use the event ID or verification ID as the dedupe key, and make database writes safe to retry.
Never trust a webhook without checking its signature. Treat unsigned requests as unauthenticated internet traffic.

Returned claims

Verified assertions contain the values permitted by the saved policy, including selected identity fields. Failed results do not disclose those values. An mDL driving_license assertion proves presentation of the requested element; it does not establish legal driving entitlement. Existing policies retain their stored output selection. If you write test fixtures for your webhook handler, include api_version: "v1" and contract_revision. The current contract revision is v1.2026-09-01.1.