The user.update.complete event intentionally does not fire when the verified flag changes through email verification. This is by design.
Email verification is considered a distinct workflow separate from the general user update process in FusionAuth's event model. As noted in a related GitHub issue, the decision was made to introduce dedicated verification events rather than triggering user.update.complete because email verification "does not occur due to the Update User API, but because of a separate workflow." The user.update.complete event is reserved for changes made through the Update User API, while verification-specific changes trigger their own dedicated events.
Recommended SolutionYou should listen to these specific webhook events for verification state changes:
user.email.verified — fires when an email address is verified (available since 1.8.0) user.identity.verified — fires when an identity (email or phone number) is verified (available since 1.59.0) Handling Race ConditionsIf you're concerned about race conditions when multiple events fire simultaneously:
Adjust your Kafka partitioning strategy to key on userId — this ensures all events for the same user go to the same partition and are processed in order Use event timestamps in your downstream consumers to deduplicate or order events correctly. Each event includes a createInstant field in the event object that can be used for ordering Design your sync logic to be idempotent so that processing events out of order doesn't cause inconsistent stateThe separate user.email.verified and user.identity.verified events provide more granular control over what verification changes you respond to, which is generally more useful than a generic user update event.
Related Documentation User Update Complete Event — documentation for the user.update.complete event User Email Verified Event — documentation for the user.email.verified event User Identity Verified Event — documentation for the user.identity.verified event Kafka Integration — comprehensive guide to FusionAuth's Kafka integration for consuming webhook events Webhook Event Log — review events sent by FusionAuth with timing and result information