Skip to main content
WEBHOOK

Authorizations

X-Hook0-Signature
string
header
required

HMAC-SHA256 signature of the raw request body, computed using your webhook secret. Webhook receivers should always verify this header before processing the event. The header value is hex-encoded and prefixed by the algorithm and timestamp, e.g. t=1700000000,v1=abc123... (refer to the Webhook Security docs for the exact verification algorithm).

This scheme applies to webhook delivery (outbound POSTs from CDP to your endpoint), not to inbound CDP API requests.

Body

application/json

The acceptance.mandate.approval_failed webhook event payload.

The acceptance.mandate.approval_failed event. data carries the full mandate and the failed approval.

eventId
string<uuid>
required

Unique identifier for this webhook event. Use this for idempotency.

Example:

"123e4567-e89b-12d3-a456-426614174000"

timestamp
string<date-time>
required

When this event occurred (ISO 8601 format).

Example:

"2025-06-01T12:00:00Z"

data
object
required

The data payload for every mandate webhook event. Always contains the full mandate. Action events also carry the relevant sub-resource: approval on the three approval_* events, revocation on the three revocation_* events. The created and canceled events carry only the mandate.

mandate.status reflects only the latest action. Read mandate.canceledAt and mandate.revokedAt to know what has durably happened: the on-chain spending allowance is gone precisely when revokedAt is set, and canceling alone does not remove it.

Example:
eventType
enum<string>
required

The type of webhook event.

Available options:
acceptance.mandate.approval_failed
Example:

"acceptance.mandate.approval_failed"

Response

Webhook received and processed successfully.