Skip to main content
Webhook subscriptions let your integration receive supported Peerlogic events as they occur. A subscription connects one practice and one trigger type to an HTTPS endpoint that you control. Use the Subscriptions and events API reference for complete request and response schemas. This guide explains the delivery flow and the responsibilities of your webhook receiver.

How webhook delivery works

1

Create a subscription

Create a webhook subscription for a practice, trigger type, and HTTPS destination.
2

Store the secret key

The create response includes a secret_key. Store it securely and associate it with the returned subscription id.
3

Receive the event

Peerlogic sends an HTTP POST request to your destination. The request body is a Fernet token and the headers identify the subscription and practice.
4

Decrypt the event

Use X-Subscription-ID to select the corresponding secret key, then decrypt the request body with a compatible Fernet implementation.
5

Process and acknowledge

Parse the decrypted JSON event and return a successful 2xx response after your endpoint accepts it.

Create a webhook subscription

Send an authenticated request to POST /api/subscriptions/. The destination must use HTTPS.
The create response includes the subscription and its encryption key:
The secret_key is returned only when you create the subscription. It cannot be retrieved or changed later. Store it in a secrets manager, never expose it in client-side code or logs, and associate it with the subscription id. If the key is lost or exposed, delete the subscription and create a replacement.
See Create subscriptions for the current trigger types and complete schema.

Receive an event

Webhook deliveries use POST with a text/plain body containing the encrypted Fernet token. Do not treat the request body as JSON until after you decrypt it.

Decrypt the request body

Use a Fernet implementation for your language. The receiver should follow this sequence:
  1. Read X-Subscription-ID from the request headers.
  2. Look up the secret key stored for that subscription.
  3. Decrypt the raw request body as a Fernet token.
  4. Parse the decrypted plaintext as JSON.
  5. Validate that the envelope identifies the expected subscription and practice.
The decrypted event uses this envelope:
The contents of data depend on the subscription trigger. Treat the API reference as the contract for supported values and retrieve related resources through the API when your workflow needs additional information.
A webhook event is a notification, not necessarily a complete representation of every related resource. For example, a caller-recognition workflow can use the event identifiers and phone data to retrieve the current contact, patient, appointment, or call details from the corresponding API endpoints.

Manage subscriptions

Use the subscription endpoints to review and control existing deliveries: Because each subscription has its own key, receivers that share one destination should maintain a secure mapping from subscription ID to secret key.

Receiver checklist

  • Expose an HTTPS endpoint that accepts POST requests with a text/plain body.
  • Store keys outside source code and logs.
  • Select the key using X-Subscription-ID; do not try every stored key.
  • Decrypt before parsing JSON.
  • Make event processing idempotent so repeated deliveries do not create duplicate work.
  • Return a 2xx response after accepting the event.
  • Monitor subscription is_active and system_message values for delivery problems.