> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.crisscross.money/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.crisscross.money/_mcp/server.

# A rate lock's validity window elapsed - fetch a new lock to keep transacting.

POST 

Fired when a lock reaches `expiresAt` without being cancelled first. The lock is now
terminal and can no longer be used for new checkouts; call `POST /v1/rate-locks` to
obtain a fresh lock.


Reference: https://docs.crisscross.money/api-reference/collect/rate-locks/rate-lock-webhooks/rate-lock-expired

## Request

### Payload

- `eventType` (string, required) — The event type, e.g. `rate_lock.cancelled` or `rate_lock.expired`.
- `timestamp` (datetime, required) — When the event was generated.
- `payload` (RateLock, required)

## Types

### RateLock

- `rateLockId` (string, required)
- `status` (enum, required) — Lock state at the time of the event: `cancelled` on `rate_lock.cancelled`, `expired` on `rate_lock.expired`. Both are terminal.
  - Allowed values: `active`, `expired`, `cancelled`
- `base` (string, required) — Base currency (ISO 4217).
- `quote` (string, required) — Quote currency (ISO 4217).
- `midRate` (string, required) — Reference mid-market rate the lock was priced from. `1 base = <midRate> quote`.
- `markupBps` (integer, required) — The markup applied over the mid, in basis points (100 bps = 1%).
- `allInRate` (string, required) — The rate you transact at: mid plus markup. This is the rate carried onto every transaction that uses the lock. `1 base = <allInRate> quote`.
- `createdAt` (datetime, required)
- `expiresAt` (datetime, required) — End of the lock's validity window. The lock is invalid from this time even if `status` still reads `active`.
- `cancellationReason` (enum, optional) — Why the lock was cancelled. Present only on `rate_lock.cancelled`, where it is always `market_drift` — the rate moved beyond the allowed tolerance. `requested` (a cancellation you asked for) appears only when reading a lock over the REST API; it never triggers a webhook.
  - Allowed values: `market_drift`, `requested`