Fintech
Plaid Webhooks
Financial data platform. Receive events for transactions, auth, item status, and account updates.
Connecting Plaid to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into Plaid. Then:
- 1Set the webhook URL when calling /link/token/create or /item/webhook/update
- 2Paste your Hookbase ingest URL as the webhook parameter
- 3Plaid signs webhooks with JWTs — verify using the JWK endpoint
- 4Different webhook_type values correspond to different products
Signature verification
Plaid signs its webhooks with JWT (RS256) in Plaid-Verification, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if Plaid can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at Verification uses Plaid's JWK endpoint. Use the webhook_verification_key from the JWT header kid..
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
Plaid event types
7 of the events people route most often. Hookbase accepts every event Plaid sends, whether or not it is listed here.
TRANSACTIONS.SYNC_UPDATES_AVAILABLE
New transaction updates are available
TRANSACTIONS.INITIAL_UPDATE
Initial transaction pull is complete
TRANSACTIONS.HISTORICAL_UPDATE
Historical transaction pull is complete
ITEM.ERROR
An item encountered an error (e.g., login required)
AUTH.AUTOMATICALLY_VERIFIED
Auth was automatically verified
HOLDINGS.DEFAULT_UPDATE
Holdings data was updated
INCOME.VERIFICATION_STATUS_UPDATED
Income verification status changed
What a Plaid webhook looks like
A TRANSACTIONS.SYNC_UPDATES_AVAILABLE payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"webhook_type": "TRANSACTIONS",
"webhook_code": "SYNC_UPDATES_AVAILABLE",
"item_id": "item_abc123",
"initial_update_complete": true,
"historical_update_complete": true,
"environment": "production"
}Start receiving Plaid webhooks
Create a source, paste the URL into Plaid, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free