Sample - Plaid API
POST/fdx/notifications

Receive FDX notification events

Receives FDX event notifications for changes involving accounts, consent, security, maintenance, or risk. Parse type, category, and notificationPayload to determine the notification and its associated event data. Treat the endpoint as a webhook receiver and submit the required notification fields in the JSON body.

  • RetriesRetries up to 2×, 500ms backoff, 30s timeout.

11 body fields

FDX notification payload containing event metadata, participants, and notification-specific data.

notificationIdstringrequired
Id of notification
typestringrequired
Type of Notification
Allowed:ACCOUNT_TAKEOVERADDRESS_CHANGEDBALANCECONSENT_EXPIREDCONSENT_GRANTEDCONSENT_REVOKEDCONSENT_UPDATEDCUSTOMMFA_TARGET_CHANGEDPHONE_CHANGEDPLANNED_OUTAGERISK
subtypestringoptional
An optional initiator-defined event subtype code or description if the event type needs to be further categorized or described.
sentOnstringrequired
ISO 8601 date-time in format 'YYYY-MM-DDThh:mm:ss.nnn[Z|[+|-]hh:mm]' according to [IETF RFC3339](https://datatracker.ietf.org/doc/html/rfc3339)
categorystringrequired
Category of Notification
Allowed:SECURITYMAINTENANCEFRAUDCONSENTNEW_DATATOKENIZED_ACCOUNT_NUMBER
severitystringoptional
Severity level of notification
Allowed:EMERGENCYALERTWARNINGNOTICEINFO
prioritystringoptional
Priority of notification
Allowed:HIGHMEDIUMLOW
publisherobjectoptional
FDX Participant - an entity or person that is a part of a FDX API transaction
subscriberobjectoptional
FDX Participant - an entity or person that is a part of a FDX API transaction
notificationPayloadobjectrequired
Custom key-value pairs payload for a notification
urlobjectoptional
REST application constraint (Hypermedia As The Engine Of Application State)

2 status codes
200Confirms receipt of the FDX notification.
defaultReturned when the notification cannot be processed. The error response identifies the failure with `error_type`, `error_code`, and `error_message`.
error_typestringrequired
A broad categorization of the error. Safe for programmatic use.
Allowed:INVALID_REQUESTINVALID_RESULTINVALID_INPUTINSTITUTION_ERRORRATE_LIMIT_EXCEEDEDAPI_ERRORITEM_ERRORASSET_REPORT_ERRORBASE_REPORT_ERRORRECAPTCHA_ERROROAUTH_ERRORPAYMENT_ERROR
error_codestringrequired
The particular error code. Safe for programmatic use.
error_code_reasonstringoptional
The specific reason for the error code. Currently, reasons are only supported for OAuth-based item errors; `null` will be returned otherwise. Safe for programmatic use. Possible values: `OAUTH_INVALID_TOKEN`: The user's OAuth connection to this institution has been invalidated. `OAUTH_CONSENT_EXPIRED`: The user's access consent for this OAuth connection to this institution has expired. `OAUTH_USER_REVOKED`: The user's OAuth connection to this institution is invalid because the user revoked their connection.
error_messagestringrequired
A developer-friendly representation of the error code. This may change over time and is not safe for programmatic use.
display_messagestringrequired
A user-friendly representation of the error code. `null` if the error is not related to user action. This may change over time and is not safe for programmatic use.
request_idstringoptional
A unique ID identifying the request, to be used for troubleshooting purposes. This field will be omitted in errors provided by webhooks.
causesarrayoptional
In this product, a request can pertain to more than one Item. If an error is returned for such a request, `causes` will return an array of errors containing a breakdown of these errors on the individual Item level, if any can be identified. `causes` will be provided for the `error_type` `ASSET_REPORT_ERROR` or `CHECK_REPORT_ERROR`. `causes` will also not be populated inside an error nested within a `warning` object.
statusintegeroptional
The HTTP status code associated with the error. This will only be returned in the response body when the error information is provided via a webhook.
documentation_urlstringoptional
The URL of a Plaid documentation page with more information about the error
suggested_actionstringoptional
Suggested steps for resolving the error
required_account_subtypesarray<string>optional
A list of the account subtypes that were requested via the `account_filters` parameter in `/link/token/create`. Currently only populated for `NO_ACCOUNTS` errors from Items with `investments_auth` as an enabled product.
provided_account_subtypesarray<string>optional
A list of the account subtypes that were extracted but did not match the requested subtypes via the `account_filters` parameter in `/link/token/create`. Currently only populated for `NO_ACCOUNTS` errors from Items with `investments_auth` as an enabled product.

Error handling

notificationId, type, sentOn, category, and notificationPayload must be provided. type, category, severity, and priority must use their declared enum values, while sentOn must use an ISO 8601 date-time and publisher or subscriber URIs must use URI format.