data field of an event holds the event data. data.object is always the resource that the event is about, in the same shape that the REST API returns for it, without expand. If you already parse the REST response, you can parse the webhook with the same code, and a field that sajn adds to the REST object also appears in the event. Some events add fields next to object, such as data.party on party events.
data.object is a snapshot of the resource when the event happened, if a 2026-10 endpoint subscribed to the event type at that time. The snapshot doesn’t change across retries. An event without a snapshot gets data.object from the resource’s current state when GET /api/v1/events reads it. If the resource no longer exists, the list leaves the event out, and GET /api/v1/events/{id} returns 404 NOT_FOUND. Dates are ISO 8601 strings in UTC, and fields without a value are null, not missing. Events gain fields over time, so ignore fields that you don’t recognize. No event carries a national identity number; nationalId is always null.
The following table lists what data holds for each group of events:
Each event also has a reference page with its full schema, such as
document.completed.
Document events
data.object is the document. It has the same fields as GET /api/v1/documents/{id} without expand, so fields is null, and productTables holds the product tables with the recipient’s selection and quantities:
documentMeta and the party in this example are shortened. For every field, see GET /api/v1/documents/{id}.
document.created adds source, which says how the document was created. It’s null for a document created in the dashboard or through the API. For a document created from an attachment emailed to the workspace inbox, it’s the following object:
inboxType is ARCHIVE when sajn imported the attachment as an archived document with status IMPORTED, and CREATE when it became a DRAFT document.
document.expiration_extended adds previousAttributes with the earlier expiresAt, which is null if the document had none. Compare it with object.expiresAt; the new date can also be earlier than the previous one.
Comment created
document.comment.created carries the new comment in object and its thread, without its messages, in thread. A thread’s visibility is SHARED when every party sees it and INTERNAL when only the workspace does; both fire the event.
Party events
Everydocument.party.* event carries the document in object and the party that the event is about in party, in the shape that GET /api/v1/documents/{id}/parties lists it:
object and party in this example are shortened. On document.party.removed, party is the party as it was before removal, and object.parties no longer lists it.
Some party events add fields:
For example, a
document.party.updated event after an email correction carries the following extra field:
Approval request events
data.object is the approval request. An approver is { user, stage, orGroup, status, comment, resolvedAt }, where user is { id, email, name }:
approval_request.cancelled, status is CANCELLED. sajn deletes a cancelled request, so this event is the last place where it appears.
Identity check events
data.object is the identity check, with verificationUrl, audits, and data set to null, as in the list response. identity_check.failed adds failureReason, the reason that the eID provider reports, such as expiredTransaction:
object in this example is shortened. To read the verified identity, call GET /api/v1/identity-checks/{id}.
Contact and company events
data.object is the contact or the company. On contact.deleted and company.deleted, it’s the resource as it was before deletion.
Template events
data.object is the template, with fields set to null. template.updated adds previousAttributes, with the earlier values of the fields of object that changed. A change to a setting outside object sends it empty:
template.updated event per template per minute and drops the others, so previousAttributes covers only the change that fired the event.
Member events
member.added carries the member and adds via, which is INVITE when the user accepted an invitation, ADMIN when an administrator added them, and SELF when they joined on their own:
member.invited and member.invite_accepted carry the invitation:
Workspace created
workspace.created carries the new workspace. createdBy is the ID of the user who created it.
Usage limit reached
usage.limit_reached carries the quota that the organization reached:
For the current usage, call
GET /api/v1/limits.
Security events
Everysecurity.* event carries the details of the action in data.object, and the envelope’s actor says whether a user, an API key, or an OAuth app acted. Every object has the following fields:
For example, a
security.document_downloaded event carries the following data:
Payloads in API version 2026-09
An endpoint on2026-09 gets the event data in payload instead of data, in the earlier shapes: a document has title instead of name and a signers array, party events carry { document, party }, and security events carry the actor inside the payload. For every difference, see Upgrading to 2026-10.
