{
"event": "verification.failed",
"data": {
"id": "b7e5c2b0-9c1a-4e2f-8f2a-3a6b0e9d1c44",
"status": "failed",
"application_id": "c2a10f3e-8b7a-4d2e-9c1a-1a2b3c4d5e6f",
"reference": "order-42",
"channel": "sms",
"to": "+966551234567",
"mode": "live",
"attempts": 3,
"expires_at": "2026-09-01T12:34:56.789Z",
"verified_at": null,
"created_at": "2026-09-01T12:29:56.789Z",
"external_id": "store_88"
},
"sent_at": "1788265862201"
}Verification failed partner
verification.failed. Opt-in. The attempts ran out, or the send failed. Sent to the partner webhook when the partner subscribed to it, with the partner’s external_id in the data. Verify tawked-signature against the raw body before trusting it, and make handling idempotent: a delivery can arrive more than once, and deliveries are not guaranteed to arrive in order.
{
"event": "verification.failed",
"data": {
"id": "b7e5c2b0-9c1a-4e2f-8f2a-3a6b0e9d1c44",
"status": "failed",
"application_id": "c2a10f3e-8b7a-4d2e-9c1a-1a2b3c4d5e6f",
"reference": "order-42",
"channel": "sms",
"to": "+966551234567",
"mode": "live",
"attempts": 3,
"expires_at": "2026-09-01T12:34:56.789Z",
"verified_at": null,
"created_at": "2026-09-01T12:29:56.789Z",
"external_id": "store_88"
},
"sent_at": "1788265862201"
}Authorizations
Authorization: Bearer . An application key (tk_live_, tk_test_) has full access, which covers every product and any product added later, or custom access, chosen when the key is created: one or more of the scopes verify:check, verify:send (includes verify:check), notifications:read, notifications:send (includes notifications:read). A call outside the key's access answers 403 insufficient_scope and names the scope it needs in the WWW-Authenticate response header. A partner key (tk_partner_) always has full access. Whatever its access, a key is a server-side secret.
Headers
Milliseconds since the epoch, as a string; the same value as sent_at.
Hex HMAC-SHA256 of "{timestamp}.{raw body}" with your webhook secret.
The event name, the same as event in the body.
verification.failed Response
Any 2xx answer within 5 seconds acknowledges the delivery. Anything else, a redirect or no answer in time is retried: 5 attempts in all, the first at once and the next after 1 min, 5 min, 30 min, 2 h.