A patient's medical insurance is checked with the insurer
What Practor sends for coverage.verified.
Webhook events
Sent to your endpoint as coverage.verified.
Sent as coverage.verified. Answer with any 2xx within 10 seconds. Anything else is retried with backoff, up to 8 attempts; an endpoint that keeps failing for three days is turned off and the practice is told. Verify the signature before you trust the body, and use id to ignore a repeat.
Body
A POST with a JSON body. It names what changed and where to read it, never the
patient data itself: read the resource with your key.
-
idstring RequiredUnique per event, and the same on every retry of it. Use it to ignore a repeat.
-
type"coverage.verified" Required -
occurredAtstring RequiredWhen it happened, as an ISO 8601 date-time in UTC.
-
dataobject Required-
object"coverage" RequiredThe coverage that was checked. Read it for
verificationStatusandverificationMessage. -
idstring Required -
urlstring or null RequiredWhere to read it with your key.
-
{
"id": "k2m9x7c4v5b8n1m3q6w9e2r5",
"type": "coverage.verified",
"occurredAt": "string",
"data": {
"object": "coverage",
"id": "c9d1f4g7h2j5k8l0z3x6v1bn",
"url": "string"
}
} Headers
Signed with the Standard Webhooks scheme. Verify the signature before you trust the body.
-
webhook-idstring Required -
The event id.
-
webhook-timestampstring Required -
Seconds since the Unix epoch when it was sent.
-
webhook-signaturestring Required -
Proves the delivery came from Practor. Check it before you trust the body: it's
v1,then the base64 HMAC-SHA256 of<webhook-id>.<webhook-timestamp>.<body>, keyed with your endpoint's secret (drop thewhsec_prefix, then base64-decode it). It follows the Standard Webhooks scheme, so any Standard Webhooks library can check it for you.