Called by Plaid, no sign-in. When Plaid reports that an end customer's OAuth registration is approved, the matching organization's Plaid account is enabled; other events are ignored. Answers with received: true. The request must carry Plaid's Plaid-Verification signature; while the plaid-webhook-verification flag is on, a missing or invalid signature gets 401.
POST
/plaid-partner/customer/webhooks/plaid
curl \
--request POST 'http://api.example.com/plaid-partner/customer/webhooks/plaid' \
--header "Authorization: Bearer $ACCESS_TOKEN" \
--header "organization: string"
Response examples (200)
{
"data": {
"received": true
},
"statusCode": 200,
"timestamp": "2026-01-15T10:15:00.000Z"
}