Skip to main content

Payload of the user.session.created webhook event. Extends Session with the user's verified credentials at session-create time so consumers can attribute the login without a follow-up API call.

verifiedCredentials
object[]
required

All verified credentials (wallets, emails, phone numbers, social accounts) linked to the user at the time the session was created.

id
string
Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

createdAt
string<date-time>

ISO 8601 timestamp of when the session was created

ipAddress
string | null

IP address of the client that initiated the session

userAgent
string | null

User-Agent string of the client that initiated the session

revokedAt
string<date-time> | null

ISO 8601 timestamp of when the session was revoked, or null if still active