Very Good Security · AsyncAPI Specification
Very Good Security Webhooks
Version
View Spec
View on GitHub
CompanyData SecurityTokenizationPaymentsVaultPCI ComplianceData PrivacyCard ManagementNetwork TokensSecurityAsyncAPIEvents
AsyncAPI Specification
generated: '2026-07-21'
method: searched
source: https://docs.verygoodsecurity.com/enterprise-platform/developer-resources/webhook-notifications
spec_type: Webhooks
notes: >-
VGS documents a real webhook notification surface but publishes no AsyncAPI
document — captured here as a webhook catalog. Configured in the VGS Dashboard
(Administration > Organization Settings > Notifications).
delivery:
mechanism: HTTPS webhook
signature_header: vgs-signature
signature_format: t=<timestamp>,v0=<sha256_hmac_of_raw_body>
verification: HMAC-SHA256 over the raw request body with a shared secret; timestamp checked within a ~60s delivery window
retries: 8 delivery attempts on non-200 responses, from immediate through ~10 hours, then cancelled
events:
- scope: VAULT
names:
- route.created
- route.updated
- route.delete
- proxy.upstream_error
- alias.reveal_failed
- scope: ORGANIZATION
names:
- vault.created
- scope: USER
names:
- user.permissions_updated
- user.permissions_deleted
- user.logged_in
- user.password_updated
- user.mfa_created
- user.mfa_deleted
- scope: CMP
docs: https://docs.verygoodsecurity.com/cmp/developer-resources/notifications
names:
- cmp_au_card.updated
- cmp_au_card.expired
- cmp_au_card.closed
- cmp_au_card.non_participating
- cmp_au_card.contact_cardholder_advice
- cmp_au_card.unknown
- cmp_au_card.enrolled
- cmp_au_card.opt_out
- cmp_au_card.enrollment_failed
- cmp_network_token.updated
- cmp_threeds.device_fingerprint
- cmp_threeds.challenge_result
Work with this as data
Every AsyncAPI spec here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for asyncapi
4 MCP tools reach this
find_asyncapisBrowse and filter every AsyncAPI spec in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This AsyncAPI spec
curl "https://apis.io/api/v1/asyncapis/very-good-security-webhooks"
All asyncapi
curl "https://apis.io/api/v1/asyncapis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.