# DROP Webhook Notifications

**Canonical:** https://apis.io/apis/california-privacy-protection-agency/drop-webhook-notifications/  
**Provider:** California Privacy Protection Agency — https://apis.io/providers/california-privacy-protection-agency/  
**Base URL:** https://api.drop.privacy.ca.gov  
**Documentation:** https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/reference/

DROP Webhook Notifications is one of 2 APIs that [California Privacy Protection Agency](https://apis.io/providers/california-privacy-protection-agency/) publishes on the [APIs.io](https://apis.io/) network. Tagged areas include Webhook and Data Brokers. The published artifact set on APIs.io includes API documentation.

Optional outbound HTTPS webhook notifications from DROP to a data broker's endpoint, enabled in the Data Broker Portal notification settings. Five event types (download.ready, upload.received, upload.processed, amendment.received, amendment.processed) are delivered with X-Webhook-* headers and an HMAC-SHA256 signature over "<timestamp>.<raw body>" using a per-broker signing secret. Documented in prose in the DROP technical reference and the OpenAPI info block; no AsyncAPI is published.

## Machine-readable artifacts (2)

- **Webhooks** — https://raw.githubusercontent.com/api-evangelist/california-privacy-protection-agency/refs/heads/main/asyncapi/california-privacy-protection-agency-drop-webhooks.yml
- **Documentation** — https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/reference/

## Other California Privacy Protection Agency APIs (1)

- [DROP Data Broker API](https://apis.io/apis/california-privacy-protection-agency/drop-data-broker-api/)

## Tags

Webhook, Data Brokers

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/california-privacy-protection-agency/drop-webhook-notifications/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/california-privacy-protection-agency/.
