Skip to content

The webhook payload

This is what UpPass POSTs to your receiver when an applicant submits. Every field is specified — read this page and the six that follow and you have everything needed to implement against it, in any language.

The examples below are the same bytes these files contain. Fetch them into your test fixtures rather than copying from the page.

Terminal window
curl -O https://docs.uppass.io/examples/webhook-submit_form-clean.json
curl -O https://docs.uppass.io/examples/webhook-submit_form-aml-hit.json
curl -O https://docs.uppass.io/examples/webhook-drop_off.json
FieldTypeReq.Notes
eventobject<EventMeta>yesMetadata about this delivery. Always present.
applicationobject<Application>yesIdentifiers and outcomes for the application. Always present.
answersobject<AnswerMap>Every captured value, keyed by question_key — OCR output from the document, answers the applicant typed, and any input parameters you passed at creation.
extraobject<WebhookExtra>Verification artefacts. Answers are not here — they are the top-level answers object.

Four objects. event and application are always present. answers and extra are present on submit_form and absent from lifecycle events.

An applicant who passed every check, with no AML match. Every branch of the structure is present — including extra.identity_aml, whose hits array is empty because nothing matched.

webhook-submit_form-clean.json
{
"event": {
"nounce": "SjG5y60YsKnnTHBxiGWVrI8FDAcXC3",
"type": "submit_form",
"version": 2,
"created_at": "2026-08-26T09:51:56.458646+00:00"
},
"application": {
"form": "YOUR_FORM_SLUG",
"id": 100002,
"no": "COK00100002",
"slug": "YOUR_APPLICATION_SLUG",
"submitted_at": "2026-08-26T09:51:48.165780+00:00",
"status": "complete",
"other_status": {
"ekyc": "pass"
}
},
"answers": {
"consent_version": {
"value": "",
"created_at": "2026-08-26T09:51:09.072084+00:00",
"updated_at": "2026-08-26T09:51:09.072096+00:00"
},
"consent_date": {
"value": "2026-08-26T09:51:06.156Z",
"created_at": "2026-08-26T09:51:09.072168+00:00",
"updated_at": "2026-08-26T09:51:09.072173+00:00"
},
"consent_checkbox_1": {
"value": true,
"created_at": "2026-08-26T09:51:09.072227+00:00",
"updated_at": "2026-08-26T09:51:09.072233+00:00"
},
"ekyc_document_type": {
"value": "passport",
"created_at": "2026-08-26T09:51:14.907185+00:00",
"updated_at": "2026-08-26T09:51:14.907210+00:00"
},
"document_number": {
"value": "AB0000001",
"created_at": "2026-08-26T09:51:21.629758+00:00",
"updated_at": "2026-08-26T09:51:21.629782+00:00"
},
"name_prefix": {
"value": "Mr.",
"created_at": "2026-08-26T09:51:21.663374+00:00",
"updated_at": "2026-08-26T09:51:21.663393+00:00"
},
"full_name_type": {
"value": "parts",
"created_at": "2026-08-26T09:51:21.738390+00:00",
"updated_at": "2026-08-26T09:51:21.738409+00:00"
},
"full_name_first_name": {
"value": "Somchai",
"created_at": "2026-08-26T09:51:21.684738+00:00",
"updated_at": "2026-08-26T09:51:21.684753+00:00"
},
"full_name_last_name": {
"value": "Jaidee",
"created_at": "2026-08-26T09:51:21.709491+00:00",
"updated_at": "2026-08-26T09:51:21.709510+00:00"
},
"full_name_en_first_name": {
"value": "Somchai",
"created_at": "2026-08-26T09:51:21.891338+00:00",
"updated_at": "2026-08-26T09:51:21.891357+00:00"
},
"full_name_en_last_name": {
"value": "Jaidee",
"created_at": "2026-08-26T09:51:21.912462+00:00",
"updated_at": "2026-08-26T09:51:21.912479+00:00"
},
"gender": {
"value": "M",
"created_at": "2026-08-26T09:51:21.870009+00:00",
"updated_at": "2026-08-26T09:51:21.870026+00:00"
},
"date_of_birth": {
"value": "1996-08-16",
"created_at": "2026-08-26T09:51:21.761786+00:00",
"updated_at": "2026-08-26T09:51:21.761805+00:00"
},
"date_of_issue": {
"value": "2024-02-07",
"created_at": "2026-08-26T09:51:21.783307+00:00",
"updated_at": "2026-08-26T09:51:21.783321+00:00"
},
"date_of_expiry": {
"value": "2034-02-06",
"created_at": "2026-08-26T09:51:21.802611+00:00",
"updated_at": "2026-08-26T09:51:21.802629+00:00"
},
"home_address_country": {
"value": "THA",
"created_at": "2026-08-26T09:51:21.847874+00:00",
"updated_at": "2026-08-26T09:51:21.847893+00:00"
}
},
"extra": {
"ekyc": {
"face_compare": {
"status": "match",
"score": 88.09
},
"liveness": {
"url": "https://app.uppass.io/api/ekyc/YOUR_APPLICATION_SLUG/result/image/?q=SIGNED_TOKEN_REDACTED&exp=1787738816",
"attempts": [
{
"attempt": 1,
"id": 100012,
"created_at": "2026-08-26T09:51:32.007437+00:00",
"status": "success",
"message": "",
"images": [
{
"url": "https://app.uppass.io/api/ekyc/YOUR_APPLICATION_SLUG/result/image/?q=SIGNED_TOKEN_REDACTED&exp=1787738816",
"action": "idle"
}
]
}
]
},
"identity_document": {
"type": "passport",
"url": "https://app.uppass.io/api/ekyc/YOUR_APPLICATION_SLUG/result/image/?q=SIGNED_TOKEN_REDACTED&exp=1787738816",
"face_image_url": "https://app.uppass.io/api/ekyc/YOUR_APPLICATION_SLUG/result/image/?q=SIGNED_TOKEN_REDACTED&exp=1787738816",
"attempts": [
{
"attempt": 1,
"id": 100013,
"created_at": "2026-08-26T09:51:21.926040+00:00",
"type": "passport",
"url": "https://app.uppass.io/api/ekyc/YOUR_APPLICATION_SLUG/result/image/?q=SIGNED_TOKEN_REDACTED&exp=1787738816",
"status": "success",
"message": ""
}
]
}
},
"identity_aml": {
"comply_advantage": [
{
"input": {
"last_name": "Jaidee",
"first_name": "Somchai",
"date_of_birth": "1996-08-16"
},
"output": {
"comply_advantage": [
{
"input": {
"last_name": "Jaidee",
"first_name": "Somchai",
"date_of_birth": "1996-08-16"
},
"output": {
"code": 200,
"status": "success",
"content": {
"data": {
"id": 1000002,
"ref": "1000002-example",
"hits": [],
"tags": [],
"limit": 500,
"labels": [],
"offset": 0,
"filters": {
"types": [],
"fuzziness": 0,
"birth_year": 1996,
"exact_match": true,
"country_codes": [],
"remove_deceased": 0
},
"client_ref": null,
"created_at": "2026-08-26 09:51:51",
"risk_level": "unknown",
"total_hits": 0,
"updated_at": "2026-08-26 09:51:51",
"assignee_id": 100000,
"search_term": "Somchai Jaidee",
"searcher_id": 100000,
"match_status": "no_match",
"total_matches": 0,
"blacklist_hits": [],
"submitted_term": "Somchai Jaidee",
"total_blacklist_hits": 0
}
}
},
"result": {
"is_found": false,
"is_in_pep": false,
"total_hits": 0,
"is_in_warnings": false,
"is_in_sanctions": false,
"is_in_adverse_media": false,
"is_in_fitness_probity": false
}
}
]
},
"result": {
"is_all_found": false,
"is_any_found": false,
"is_all_in_pep": false,
"is_any_in_pep": false,
"is_all_in_warnings": false,
"is_any_in_warnings": false,
"is_all_in_sanctions": false,
"is_any_in_sanctions": false,
"is_all_in_adverse_media": false,
"is_any_in_adverse_media": false,
"is_all_in_fitness_probity": false,
"is_any_in_fitness_probity": false
},
"timestamp": "2026-08-26T09:51:51.771894+00:00",
"values_list": [
"is_any_in_adverse_media",
"is_any_in_warnings",
"is_any_in_fitness_probity",
"is_any_in_sanctions",
"is_any_in_pep"
]
}
]
}
}
}
Timestamps ISO 8601 with a +00:00 offset — except answers.consent_date.value, which uses a Z suffix. Parse both.
Absent versus null A field that does not apply is omitted, not set to null. Do not require keys.
Numbers score is a float 0–100. Identifiers are integers.
Strings No length guarantees. extra.identity_aml in particular is unbounded.
Casing other_status.ekyc is lower-case; the configured status columns are Title-case. Compare case-insensitively.