---
title: "Get webhook verification key"
method: POST
path: "/webhook_verification_key/get"
tags: ["plaid"]
---

# Get webhook verification key

`POST /webhook_verification_key/get`

Plaid signs all outgoing webhooks and provides JSON Web Tokens (JWTs) so that you can verify the authenticity of any incoming webhooks to your application. A message signature is included in the `Plaid-Verification` header.

The `/webhook_verification_key/get` endpoint provides a JSON Web Key (JWK) that can be used to verify a JWT.

## Request body

- WebhookVerificationKeyGetRequest — WebhookVerificationKeyGetRequest defines the request schema for `/webhook_verification_key/get`
  - `client_id` string — Your Plaid API `client_id`. The `client_id` is required and may be provided either in the `PLAID-CLIENT-ID` header or as part of a request body.
  - `secret` string — Your Plaid API `secret`. The `secret` is required and may be provided either in the `PLAID-SECRET` header or as part of a request body.
  - `key_id` string, required — The key ID ( `kid` ) from the JWT header.

## Response `200`

OK

- WebhookVerificationKeyGetResponse — WebhookVerificationKeyGetResponse defines the response schema for `/webhook_verification_key/get`
  - `key` JWKPublicKey, required — A JSON Web Key (JWK) that can be used in conjunction with [JWT libraries](https://jwt.io/#libraries-io) to verify Plaid webhooks
    - `alg` string, required — The alg member identifies the cryptographic algorithm family used with the key.
    - `crv` string, required — The crv member identifies the cryptographic curve used with the key.
    - `kid` string, required — The kid (Key ID) member can be used to match a specific key. This can be used, for instance, to choose among a set of keys within the JWK during key rollover.
    - `kty` string, required — The kty (key type) parameter identifies the cryptographic algorithm family used with the key, such as RSA or EC.
    - `use` string, required — The use (public key use) parameter identifies the intended use of the public key.
    - `x` string, required — The x member contains the x coordinate for the elliptic curve point, provided as a base64url-encoded string of the coordinate's big endian representation.
    - `y` string, required — The y member contains the y coordinate for the elliptic curve point, provided as a base64url-encoded string of the coordinate's big endian representation.
    - `created_at` integer, required — The timestamp when the key was created, in Unix time.
    - `expired_at` integer, nullable, required — The timestamp when the key expired, in Unix time.
  - `request_id` string, required — A unique identifier for the request, which can be used for troubleshooting. This identifier, like all Plaid identifiers, is case sensitive.

## Other responses

- `default` — Error response

## Changes

- **2026-07-22** `a1bbca018160` — 13 warning
  - added the new `ASSETS_ERROR` enum value to the `error_type` response property for the response status `default`
  - added the new `CRA_MONITORING_ERROR` enum value to the `error_type` response property for the response status `default`
  - added the new `CREDIT_PROFILE_REPORT_ERROR` enum value to the `error_type` response property for the response status `default`
  - added the new `ENCOMPASS_ERROR` enum value to the `error_type` response property for the response status `default`
  - …9 more
- **2026-06-25** `80d23bfdc2e5` — 1 warning
  - added the new `IDEMPOTENCY_ERROR` enum value to the `error_type` response property for the response status `default`
- **2026-06-10** `fb8c3f188d8b` — 1 warning
  - added the new `BASE_REPORT_ERROR` enum value to the `error_type` response property for the response status `default`
- **2025-12-11** `465584b48c99` — 2 info
  - added the optional property `provided_account_subtypes` to the response with the `default` status
  - added the optional property `required_account_subtypes` to the response with the `default` status
- **2025-11-19** `4abee1c56929` — 1 info
  - removed the `IDENTITY_ERROR` enum value from the `error_type` response property for the response status `default`

[Change history](https://skmtc.dev/plaid/apis/the-plaid-api/changes/webhook_verification_key/get/post.md)

---

[API](https://skmtc.dev/plaid/apis/the-plaid-api.md) · [All operations](https://skmtc.dev/plaid/apis/the-plaid-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/plaid/the-plaid-api/revisions/a1bbca018160/schema)
