How webhook delivery works
1
Create a subscription
Create a
webhook subscription for a practice, trigger type, and HTTPS destination.2
Store the secret key
The create response includes a
secret_key. Store it securely and associate it with the returned subscription id.3
Receive the event
Peerlogic sends an HTTP
POST request to your destination. The request body is a Fernet token and the headers identify the subscription and practice.4
Decrypt the event
Use
X-Subscription-ID to select the corresponding secret key, then decrypt the request body with a compatible Fernet implementation.5
Process and acknowledge
Parse the decrypted JSON event and return a successful
2xx response after your endpoint accepts it.Create a webhook subscription
Send an authenticated request toPOST /api/subscriptions/. The destination must use HTTPS.
Receive an event
Webhook deliveries usePOST with a text/plain body containing the encrypted Fernet token.
Do not treat the request body as JSON until after you decrypt it.
Decrypt the request body
Use a Fernet implementation for your language. The receiver should follow this sequence:- Read
X-Subscription-IDfrom the request headers. - Look up the secret key stored for that subscription.
- Decrypt the raw request body as a Fernet token.
- Parse the decrypted plaintext as JSON.
- Validate that the envelope identifies the expected subscription and practice.
data depend on the subscription trigger. Treat the API reference as the contract for supported values and retrieve related resources through the API when your workflow needs additional information.
A webhook event is a notification, not necessarily a complete representation of every related resource. For example, a caller-recognition workflow can use the event identifiers and phone data to retrieve the current contact, patient, appointment, or call details from the corresponding API endpoints.
Manage subscriptions
Use the subscription endpoints to review and control existing deliveries:- List subscriptions and filter them by practice, active state, or name.
- Get a subscription to inspect its current configuration and
system_message. - Update a subscription to change its name, description, or active state.
- Delete a subscription when the destination or encryption key must be replaced.
Receiver checklist
- Expose an HTTPS endpoint that accepts
POSTrequests with atext/plainbody. - Store keys outside source code and logs.
- Select the key using
X-Subscription-ID; do not try every stored key. - Decrypt before parsing JSON.
- Make event processing idempotent so repeated deliveries do not create duplicate work.
- Return a
2xxresponse after accepting the event. - Monitor subscription
is_activeandsystem_messagevalues for delivery problems.