# user.tags_updated

Sent to the webhook endpoints subscribed to `user.tags_updated` in `event_types`. The resource type of this event, used as the key of `resource_filters`, is `user`.

## Example body

```json
{
  "id": "evt_01J8Z3TESTE",
  "type": "user.tags_updated",
  "version": 1,
  "occurred_at": "2026-09-29T12:00:00Z",
  "data": {
    "id": "usr_42",
    "tag_ids": [
      "tag_42"
    ]
  },
  "delivery_id": "whd_01J8Z3TESTE",
  "attempt": 1
}
```

With `payload_detail` set to `masked` or `full`, the body also carries `expanded` with `user`, each in the same format as the API returns it. See [API webhooks](https://cademi.dev/api/webhooks.md).

## Fields

| Field | Type | Required | Description |
|---|---|---|---|
| `id` | string | yes | ID of the event, prefixed with `evt_`, as in `GET /events/{event_id}`. Every delivery and retry of the same event has the same ID. |
| `type` | string | yes | Always `user.tags_updated`. |
| `version` | integer | yes | Always `1`. Version of the format of `data` for this event type. |
| `occurred_at` | string | yes | When the event occurred, in UTC. |
| `data` | object | yes | Data of the event, in the format of its `version`. People are identified only by ID. The only free text is the note written by whoever operates the account (`reason` in `certificate.revoked` and `diamond_membership.stage_changed`), sent as written. |
| `data.id` | string | yes | Public ID of the user, prefixed with `usr_`. |
| `data.tag_ids` | array of string | yes | Public IDs of all the tags of the user after the change, prefixed with `tag_`. |
| `expanded` | object | no | Present only when the `payload_detail` of the endpoint is `masked` or `full`. Contains the resources the event refers to, in the same format as the API returns them, as they were when the delivery was created: a retry sends the same objects. A key is `null` when the resource no longer exists. In `masked`, personal data is masked by the rules described in `payload_detail` of `POST /webhooks` (`re**@g**.com`, `Renan C** P**`), and free text written by users is replaced with `[redacted]`; a masked value keeps the type of the field, but may not match its `format` (a masked email is not a valid address). Masked personal data is still personal data. In `full`, values are sent as stored. |
| `delivery_id` | string | yes | ID of this delivery, prefixed with `whd_`, as in `GET /webhooks/{webhook_id}/deliveries/{webhook_delivery_id}`. Every retry of the delivery has the same ID. |
| `attempt` | integer | yes | Number of this attempt of the delivery, starting at 1. |

Your endpoint answers with any `2xx` status to confirm the delivery. See [Deliveries and retries](https://cademi.dev/webhooks/deliveries.md).
