Skip to main content
Fired when an existing authenticator on a user is updated, such as when the user’s SMS channel switches between SMS and WhatsApp, or when a device calls updateCredential to rotate its push token or reset its credential expiry. This webhook is asynchronous. If your endpoint returns a non-2xx response, it is retried up to 3 times, at least 30 seconds apart. Configure the webhook URL for authenticator events in tenant settings.

Payload

string
required
The ID of the user the authenticator was updated for.
string
required
The verification method of the authenticator that was updated.
string
required
The time the authenticator was updated in ISO 8601 format.
string
required
A unique ID for the user authenticator that was updated.
string
The time the credential expires, in ISO 8601 format. Only included when a push credential is updated and a credential lifetime is configured.
string
The last channel that was used to successfully complete an SMS OTP challenge. Either DEFAULT (regular SMS) or WHATSAPP.
string
The email address associated with the authenticator. Included for email OTP and magic link authenticators.
string
The phone number associated with the authenticator. Included for SMS and WhatsApp authenticators.
string
The passkey credential ID. Only included for passkey authenticators.
string
The AAGUID of the authenticator that created the passkey. Only included for passkey authenticators.
string
A display name for the passkey authenticator, such as the device or credential manager name. Only included for passkey authenticators.