Skip to main content
customer.restricted is off by default. It will not be delivered until you enable it in Dashboard → Developers. See Receiving Webhooks for instructions.
Fired when a customer’s deposit or withdrawal access is restricted inside Soap — by a dashboard user or by automated checks (for example KYC failure or multi-accounting). The matching lift is customer.unrestricted, which uses the same payload shape. This is a customer event, not a checkout event. The payload has no charge, line_items, or subscription fields.

Payload Structure

  • type is which restriction flag changed, not the webhook event name.
  • user is { "email": "..." } when a dashboard user applied the restriction, and null when Soap applied it automatically or when the sandbox $1.13 simulation produced it.
  • created_at is a Ruby-formatted timestamp string ("2026-08-25 18:20:59 UTC"), not ISO 8601.
  • reason_code says why the restriction was applied. See Reason codes.

Reason codes

reason_code is a string when Soap applied the restriction automatically and null when no automatic reason was recorded. Unless noted, a code restricts both deposits and withdrawals. New codes may be added over time, so treat any unrecognized value with a generic fallback rather than rejecting the event. For KYC_DOES_NOT_MATCH_PROFILE_NAME, correct the profile with Update Customer — use the customer’s legal first name and surname as shown on their ID, with no nicknames, middle names, initials or suffixes in those fields — and then lift the restriction in the dashboard.

Example Response

Dashboard-initiated example, with an acting user: