FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    Why doesn't user.update.complete fire when email verification changes verified flag?

    Scheduled Pinned Locked Moved Solved
    Frequently Asked Questions (FAQ)
    webhooks kafka events email verification
    1
    2
    18
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by

      When using FusionAuth's email verification flow, the verified flag in user.data changes, but the user.update.complete webhook event does not fire.

      We sync user state to external systems through the Kafka integration (using Azure Event Hub's Kafka endpoints). We expected user.update.complete to fire for all user mutations, including when the verified flag changes during the email verification process.

      Without this event firing, we have to listen to both user.update.complete and user.email.verified events. However, since both events contain the verified flag on the user object and can fire simultaneously, this creates race conditions downstream — the Kafka integration doesn't guarantee ordering unless the partitioning strategy is keyed on userId.

      Why doesn't user.update.complete fire when email verification changes the verified state? Is there a recommended approach to handle this scenario without encountering race conditions?

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by

        The user.update.complete event intentionally does not fire when the verified flag changes through email verification. This is by design.

        Email verification is considered a distinct workflow separate from the general user update process in FusionAuth's event model. As noted in a related GitHub issue, the decision was made to introduce dedicated verification events rather than triggering user.update.complete because email verification "does not occur due to the Update User API, but because of a separate workflow." The user.update.complete event is reserved for changes made through the Update User API, while verification-specific changes trigger their own dedicated events.

        Recommended Solution

        You should listen to these specific webhook events for verification state changes:

        • user.email.verified — fires when an email address is verified (available since 1.8.0)
        • user.identity.verified — fires when an identity (email or phone number) is verified (available since 1.59.0)

        Handling Race Conditions

        If you're concerned about race conditions when multiple events fire simultaneously:

        1. Adjust your Kafka partitioning strategy to key on userId — this ensures all events for the same user go to the same partition and are processed in order
        2. Use event timestamps in your downstream consumers to deduplicate or order events correctly. Each event includes a createInstant field in the event object that can be used for ordering
        3. Design your sync logic to be idempotent so that processing events out of order doesn't cause inconsistent state

        The separate user.email.verified and user.identity.verified events provide more granular control over what verification changes you respond to, which is generally more useful than a generic user update event.

        Related Documentation

        • User Update Complete Event — documentation for the user.update.complete event
        • User Email Verified Event — documentation for the user.email.verified event
        • User Identity Verified Event — documentation for the user.identity.verified event
        • Kafka Integration — comprehensive guide to FusionAuth's Kafka integration for consuming webhook events
        • Webhook Event Log — review events sent by FusionAuth with timing and result information

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • First post
          Last post