Skip to main content
Webhook events

Sent to your endpoint as claim.status_changed.

Sent as claim.status_changed. Answer with any 2xx within 10 seconds. Anything else is retried with backoff, up to 8 attempts; an endpoint that keeps failing for three days is turned off and the practice is told. Verify the signature before you trust the body, and use id to ignore a repeat.

Body

A POST with a JSON body. It names what changed and where to read it, never the patient data itself: read the resource with your key.

  • id string Required

    Unique per event, and the same on every retry of it. Use it to ignore a repeat.

  • type "claim.status_changed" Required
  • occurredAt string Required

    When it happened, as an ISO 8601 date-time in UTC.

  • data object Required
    • object "invoice" Required

      What the event is about. A claim or payment event names the invoice it belongs to.

    • id string Required
    • url string or null Required

      Where to read it with your key.

Example body
{
  "id": "k2m9x7c4v5b8n1m3q6w9e2r5",
  "type": "claim.status_changed",
  "occurredAt": "string",
  "data": {
    "object": "invoice",
    "id": "i2q6w8e0r4t7y1u3o5p9a6sd",
    "url": "string"
  }
}

Headers

Signed with the Standard Webhooks scheme. Verify the signature before you trust the body.

webhook-id string Required

The event id.

webhook-timestamp string Required

Seconds since the Unix epoch when it was sent.

webhook-signature string Required

Proves the delivery came from Practor. Check it before you trust the body: it's v1, then the base64 HMAC-SHA256 of <webhook-id>.<webhook-timestamp>.<body>, keyed with your endpoint's secret (drop the whsec_ prefix, then base64-decode it). It follows the Standard Webhooks scheme, so any Standard Webhooks library can check it for you.