{
"id": "8e14b7f2-5c39-4a06-9d8b-2f70a3c5e619",
"type": "pass.scanned",
"timestamp": "2026-08-04T08:16:30.835Z",
"correlationId": "019fcbd8-7e33-7a41-bb2f-2f0f4d5f2a11",
"data": {
"id": "019fcbd8-7e4a-71cc-a560-c92c018188b8",
"result": "accepted",
"reason": "valid",
"verified": "online",
"passId": "019fb76a-3358-7cd7-b9c2-b7f61bd0dbba",
"externalPassId": "member-8421",
"projectId": "6c2d94f7-01a8-4be3-95d7-8f34e60b1a29",
"scannedAt": "2026-08-04T08:16:30.764Z",
"recordedAt": "2026-08-04T08:16:30.771Z",
"deviceId": "dev_c71c1dccd18f5228",
"metadata": {
"note": "Main entrance"
}
}
}webhook-events
A scan was recorded
Every decision fires, accepted and denied. A scan a device decided offline arrives when that device reports it, so it can arrive well after its scannedAt.
Signed POST to your registered endpoint. Verify X-Passlet-Signature over the raw body before parsing, and deduplicate on the envelope id.
WEBHOOK
pass.scanned
{
"id": "8e14b7f2-5c39-4a06-9d8b-2f70a3c5e619",
"type": "pass.scanned",
"timestamp": "2026-08-04T08:16:30.835Z",
"correlationId": "019fcbd8-7e33-7a41-bb2f-2f0f4d5f2a11",
"data": {
"id": "019fcbd8-7e4a-71cc-a560-c92c018188b8",
"result": "accepted",
"reason": "valid",
"verified": "online",
"passId": "019fb76a-3358-7cd7-b9c2-b7f61bd0dbba",
"externalPassId": "member-8421",
"projectId": "6c2d94f7-01a8-4be3-95d7-8f34e60b1a29",
"scannedAt": "2026-08-04T08:16:30.764Z",
"recordedAt": "2026-08-04T08:16:30.771Z",
"deviceId": "dev_c71c1dccd18f5228",
"metadata": {
"note": "Main entrance"
}
}
}Body
application/json
Unique delivery ID. Use it to deduplicate retries and redeliveries.
Allowed value:
"pass.scanned"Example:
"pass.scanned"
When the delivery was created.
Pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$Correlates this delivery with the API request or job that caused it.
Show child attributes
Show child attributes
Response
2XX
Any 2xx acknowledges the delivery. Anything else is retried.