# Event Token

## event_token

- **type:** string
- **required**: true

## Response Codes

### 200 OK
**object**  
A single event that affects the transaction state and lifecycle.

- **created**  
  - **type:** date-time  
  - **required**: true  
  - **description:** An RFC 3339 timestamp for when the event was created. UTC time zone. If no timezone is specified, UTC will be used.

- **event_type**  
  - **type:** string  
  - **enum**  
  - **required**: true  
  - **description:** The type of event that occurred. Possible values:
    - account_holder_document.updated: Occurs when an account holder's document upload status has been updated.
    - account_holder.created: Occurs when a new account_holder is created.
    - account_holder.updated: Occurs when an account_holder is updated.
    - account_holder.verification: Occurs when an asynchronous account_holder's verification is completed.
    - auth_rules.backtest_report.created: Auth Rules backtest report created.
    - balance.updated: Financial Account Balance Update
    - book_transfer_transaction.created: Occurs when a book transfer transaction is created.
    - book_transfer_transaction.updated: Occurs when a book transfer transaction is updated.
    - card_authorization.challenge: Occurs when an Out of Band challenge is issued during card authorization. The card program should issue its own challenge to the cardholder and then respond via [/v1/card_authorizations/{event_token}/challenge_response](https://docs.lithic.com/reference/respondtoauthorizationchallenge).
    - card_authorization.challenge_response: Occurs when a cardholder responds to a challenge during card authorization.
    - card_transaction.enhanced_data.created: Occurs when L2/L3 enhanced commercial data is processed for a transaction event.
    - card_transaction.enhanced_data.updated: Occurs when L2/L3 enhanced commercial data is reprocessed for a transaction event.
    - card_transaction.updated: Occurs when a card transaction happens.
    - card.converted: Occurs when a card is converted from virtual to physical cards.
    - card.created: Occurs when a new card is created.
    - card.reissued: Occurs when a card is reissued.
    - card.renewed: Occurs when a card is renewed.
    - card.shipped: Occurs when a card is shipped.
    - card.updated: Occurs when a card is updated.
    - claim_document.accepted: Occurs when a claim document passes validation and is accepted.
    - claim_document.rejected: Occurs when a claim document fails validation and is rejected.
    - claim_document.uploaded: Occurs when a claim document is uploaded and begins validation.
    - claim.created: Occurs when a dispute intake claim is created.
    - claim.updated: Occurs when a dispute intake claim is updated, such as a status change or a change to its outstanding requirements.
    - digital_wallet.tokenization_result: Occurs when a tokenization request succeeded or failed. This event will be deprecated in the future. We recommend using `tokenization.result` instead.
    - digital_wallet.tokenization_two_factor_authentication_code: Occurs when a tokenization request 2FA code is sent to the Lithic customer for self-serve delivery. This event will be deprecated in the future. We recommend using `tokenization.two_factor_authentication_code` instead.
    - digital_wallet.tokenization_two_factor_authentication_code_sent: Occurs when a tokenization request 2FA code is sent to our downstream messaging providers for delivery. This event will be deprecated in the future. We recommend using `tokenization.two_factor_authentication_code_sent` instead.
    - digital_wallet.tokenization_updated: Occurs when a tokenization's status has changed. This event will be deprecated in the future. We recommend using `tokenization.updated` instead.
    - dispute_evidence.upload_failed: Occurs when an evidence upload fails for a dispute filed through the Chargebacks API (`/v1/disputes`). This event is not emitted for Managed Disputes.
    - dispute_transaction.created: Occurs when a new dispute transaction is created for a Managed Disputes case.
    - dispute_transaction.updated: Occurs when a dispute transaction for a Managed Disputes case is updated.
    - dispute.updated: Occurs when a dispute filed through the Chargebacks API (`/v1/disputes`) is created or updated. This event is not emitted for Managed Disputes. Use `dispute_transaction.created` and `dispute_transaction.updated` instead.
    - embed.session_generated: Occurs when a card embed session is successfully generated.
    - embed.viewed: Occurs when a card detail is successfully revealed through an embed.
    - external_bank_account.created: Occurs when an external bank account is created.
    - external_bank_account.updated: Occurs when an external bank account is updated.
    - external_payment.created: Occurs when an external payment is created.
    - external_payment.updated: Occurs when an external payment is updated.
    - financial_account.created: Occurs when a financial account is created.
    - financial_account.updated: Occurs when a financial account is updated.
    - funding_event.created: Occurs when a funding event is created.
    - internal_transaction.created: Occurs when an internal adjustment is created.
    - internal_transaction.updated: Occurs when an internal adjustment is updated.
    - loan_tape.created: Occurs when a loan tape is created.
    - loan_tape.updated: Occurs when a loan tape is updated.
    - management_operation.created: Occurs when a management operation is created.
    - management_operation.updated: Occurs when a management operation is updated.
    - network_total.created: Occurs when a network total is created.
    - network_total.updated: Occurs when a network total is updated.
    - payment_transaction.created: Occurs when a payment transaction is created.
    - payment_transaction.updated: Occurs when a payment transaction is updated.
    - settlement_report.updated: Occurs when a settlement report is created or updated.
    - statements.created: Occurs when a statement has been created.
    - three_ds_authentication.challenge: The `three_ds_authentication.challenge` event. Upon receiving this request, the Card Program should issue its own challenge to the cardholder. After a cardholder challenge is successfully completed, the Card Program needs to respond back to Lithic by call to [/v1/three_ds_decisioning/challenge_response](https://docs.lithic.com/reference/post_v1-three-ds-decisioning-challenge-response). Then the cardholder must navigate back to the merchant checkout flow to complete the transaction. Some merchants will include an `app_requestor_url` for app-based purchases; Lithic recommends triggering a redirect to that URL after the cardholder completes an app-based challenge.
    - three_ds_authentication.created: Occurs when a 3DS authentication is created.
    - three_ds_authentication.updated: Occurs when a 3DS authentication is updated (eg. challenge is completed).
    - tokenization.approval_request: Occurs when a tokenization approval request is made.
    - tokenization.result: Occurs when a tokenization request succeeded or failed.
    - tokenization.two_factor_authentication_code: Occurs when a tokenization request 2FA code is sent to the Lithic customer for self-serve delivery.
    - tokenization.two_factor_authentication_code_sent: Occurs when a tokenization request 2FA code is sent to our downstream messaging providers for delivery.
    - tokenization.updated: Occurs when a tokenization's status has changed.

## payload

- **type:** object
- **required**: true
- **description**: Has additional fields
- **token**  
  - **type:** string  
  - **required**: true  
  - **description:** Globally unique identifier.

## Response Codes

### Error Codes

- **400** : A parameter in the query given in the request does not match the valid queries for the endpoint.
- **401** :
  | **Description** | **Details** |
  | --- | --- |
  | User has not been authenticated | Invalid or missing API key |
  | API key is not active | The API key used is no longer active |
  | Could not find API key | The API key provided is not associated with any user |
  | Please provide API key in Authorization header | The Authorization header is not in the request |
  | Please provide API key in the form Authorization: [api-key] | The Authorization header is not formatted properly |
  | Insufficient privileges. Issuing API key required | Write access requires an Issuing API key. Reach out at [lithic.com/contact](/content/contact/index.html) |
  | Insufficient privileges to create virtual cards. | Creating virtual cards requires an additional privilege |

- **404** : The specified resource was not found.
- **429** : Client has exceeded the number of allowed requests in a given time period.  
  | **Description** | **Details** |
  | --- | --- |
  | Rate limited, too many requests per second | User has exceeded their per second rate limit |
  | Rate limited, reached daily limit | User has exceeded their daily rate limit |
  | Rate limited, too many keys tried | One IP has queried too many different API keys |

## Example

```shell
curl --request GET \
     --url https://sandbox.lithic.com/v1/events/event_token \
     --header 'accept: application/json'
```

### Example Response

```json
{
  "created": "2026-07-18T00:25:26.719Z",
  "event_type": "account_holder_document.updated",
  "payload": {},
  "token": "msg_1srOrx2ZWZBpBUvZwXKQmoEYga1"
}
```
