Skip to main content
Webhook events

Sent to your endpoint as webhook.test.

Sent as webhook.test, once, when someone at the practice picks "Send a test event" on the endpoint. Answer it like any other.

Body

A POST with a JSON body. It names what changed and where to read it, never the patient data itself: read the resource with your key.

  • id string Required
  • type "webhook.test" Required
  • occurredAt string Required
  • data object Required
    • message string Required
Example body
{
  "id": "string",
  "type": "webhook.test",
  "occurredAt": "string",
  "data": {
    "message": "string"
  }
}

Headers

Signed with the Standard Webhooks scheme. Verify the signature before you trust the body.

webhook-id string Required

The event id.

webhook-timestamp string Required

Seconds since the Unix epoch when it was sent.

webhook-signature string Required

Proves the delivery came from Practor. Check it before you trust the body: it's v1, then the base64 HMAC-SHA256 of <webhook-id>.<webhook-timestamp>.<body>, keyed with your endpoint's secret (drop the whsec_ prefix, then base64-decode it). It follows the Standard Webhooks scheme, so any Standard Webhooks library can check it for you.