Webhooks
Matches the outbound webhook design already specified in the Ecosystem Blueprint (Section 1.4.3) exactly — this page documents that design for partner consumption, it does not define a new one.
Signing
Every webhook payload is signed with HMAC-SHA256 using a shared secret issued at onboarding, rotatable on request.
Verify the signature before processing any payload. An unsigned or incorrectly-signed request should be rejected, not silently accepted.
Delivery & Retries
A failed delivery is retried on this schedule: 1s, 5s, 25s, 125s, then hourly for 24 hours. After 24 hours, the event moves to a dead-letter state and is available via the partner dashboard's event log for manual replay.
Versioning
The X-Ensure-Event-Version header changes only on a breaking schema change. Additive fields (new, optional) ship without a version bump — your integration should ignore unrecognized fields rather than fail on them.
Available Events (Phase 1)
| Event | Fires When |
|---|---|
eligibility.updated |
A member's coverage status changes |
formulary.check.completed |
A real-time NCPDP D.0 transaction your system responded to has been processed |
escalation.routed |
A case involving your integration was routed for clinician/pharmacist review |
