# expense.updated

> Sent when an expense is replaced or its file is swapped. Each event is attempted up to 3 times: the first delivery, then retries after 10 s and 100 s; only a 2xx response counts as success. The request times out after 10 seconds.

## Webhook event: POST expense.updated

Sent when an expense is replaced or its file is swapped. Each event is attempted up to 3 times: the first delivery, then retries after 10 s and 100 s; only a 2xx response counts as success. The request times out after 10 seconds.

### Request and responses

```json
{
  "servers": [
    {
      "url": "https://app.fsaskaita.lt/api",
      "description": "Production"
    }
  ],
  "operation": {
    "tags": [
      "Expenses"
    ],
    "operationId": "webhookExpenseUpdated",
    "summary": "expense.updated",
    "description": "Sent when an expense is replaced or its file is swapped. Each event is attempted up to 3 times: the first delivery, then retries after 10 s and 100 s; only a 2xx response counts as success. The request times out after 10 seconds.",
    "parameters": [
      {
        "$ref": "#/components/parameters/webhookSignature"
      }
    ],
    "requestBody": {
      "required": true,
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "required": [
              "event",
              "data"
            ],
            "properties": {
              "event": {
                "const": "expense.updated"
              },
              "data": {
                "$ref": "#/components/schemas/Expense"
              }
            }
          }
        }
      }
    },
    "responses": {
      "2XX": {
        "description": "Return any 2xx status to acknowledge the delivery. Any other status or a timeout schedules a retry."
      }
    }
  },
  "securitySchemes": {
    "bearerAuth": {
      "type": "http",
      "description": "Business token created in the app under Settings, Integrations, API. The token is scoped to exactly one business, has no expiry and is shown only once. Send it as `Authorization: Bearer <token>` together with `Accept: application/json`.",
      "scheme": "bearer"
    }
  }
}
```

### Referenced components

```json
{
  "#/components/parameters/webhookSignature": {
    "name": "Signature",
    "in": "header",
    "required": true,
    "description": "Lowercase hex HMAC-SHA256 of the raw request body, keyed with the webhook's signing secret (`whsec_…`). Recompute it over the exact bytes received and compare with a constant-time function before trusting the payload. No timestamp or event-id header is sent.",
    "schema": {
      "type": "string",
      "pattern": "^[0-9a-f]{64}$"
    },
    "example": "5f1c0d8f9a7e4b2c6d3e1f0a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5d4e3f2a1b0c"
  },
  "#/components/schemas/Expense": {
    "type": "object",
    "properties": {
      "id": {
        "type": "string",
        "format": "uuid"
      },
      "date": {
        "type": [
          "string",
          "null"
        ],
        "format": "date",
        "description": "Document date, `Y-m-d`."
      },
      "total": {
        "type": "number",
        "description": "Amount including VAT."
      },
      "currency": {
        "type": "string"
      },
      "seller": {
        "type": "string"
      },
      "created_at": {
        "type": "integer",
        "description": "Unix timestamp, seconds."
      },
      "updated_at": {
        "type": "integer",
        "description": "Unix timestamp, seconds."
      }
    },
    "required": [
      "id",
      "date",
      "total",
      "currency",
      "seller",
      "created_at",
      "updated_at"
    ],
    "title": "Expense"
  }
}
```
