---
title: "Receive a SignWell signing event (public, HMAC-authenticated)"
method: POST
path: "/compliance/msa/signatures/webhook"
tags: ["compliance", "msa", "webhooks"]
---

# Receive a SignWell signing event (public, HMAC-authenticated)

`POST /compliance/msa/signatures/webhook`

Inbound SignWell event receiver for the test-only MSA e-signature POC. Authenticated by the event's HMAC over type@time, which is why the body is treated only as a hint: the event marks a known signature request due, and the transition is made by re-reading and re-verifying the document from the vendor. Unknown documents produce no write, and the ack is constant.

## Request body

- MsasigningWebhookInput
  - `data` MsasigningWebhookDataInput
    - `object` MsasigningWebhookObjectInput
      - `id` string
  - `event` MsasigningWebhookEventInput, required
    - `hash` string, required
    - `time` integer, required
    - `type` string, required

## Response `200`

OK

- MsasigningWebhookOutput
  - `received` boolean, required

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `default` — Error response.

## Changes

- **2026-09-17** `e55170c42599` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/stablesea/apis/stable-sea-backend/changes/compliance/msa/signatures/webhook/post.md)

---

[API](https://skmtc.dev/stablesea/apis/stable-sea-backend.md) · [All operations](https://skmtc.dev/stablesea/apis/stable-sea-backend/llms.txt) · [OpenAPI document](https://skmtc.dev/stablesea/apis/stable-sea-backend/revisions/823fcbbd2f80?raw)
