Skip to main content

Webhooks

You can configure webhooks for 1-Click Health: see here in the Setup guide. This allows you to receive 1-Click Health output data asynchronously. (You can alternatively poll the GET /1-click/health endpoint.)

MethodPOST
URLDefined by webhooks brand setting
AuthenticationDefined by webhooks brand setting (None, API Key, or Basic Auth)
RetriesAfter 1 minute, 5 minutes, 30 minutes, 2 hours, 6 hours, and 12 hours (in total, about 22 hours from first attempt)
Expected responseRespond with a 2xx status (for example 200) to acknowledge receipt; a timeout or response with any other status is treated as a failed delivery and triggers a retry
DeliveryAt least once (multiple deliveries possible)
RetentionAfter final retry, undelivered event is moved to dead-letter queue (DLQ) and retained there for 14 days

Headers​

Each webhook request includes the following headers:

HeaderValueNotes
Content-Typeapplication/jsonThe payload is always sent as JSON.
User-AgentVerifiedInc-Webhook/1.0Identifies the request as coming from Verified.
X-Webhook-TimestampTimestamp used to sign the requestUse this exact value when verifying the webhook signature.
X-Webhook-Signaturev1=...HMAC-SHA256 signature of the timestamp and raw request body.

Any authentication headers you configure in your webhooks brand setting (API Key or Basic Auth) are also included.

Signatures​

When you define a webhook in the webhooks brand setting, or rotate the secret of an existing webhook, we display a new signing secret but only once: store it securely.

Verify each webhook using the signing secret for your webhook:

  1. Read the raw request body before parsing JSON, and read X-Webhook-Timestamp from the request headers.

  2. Compute the expected signature from the secret, timestamp, and raw body, then compare it with the v1 value in X-Webhook-Signature using a constant-time comparison:

    v1=HMAC-SHA256(secret, `${timestamp}.${rawBody}`)
  3. Reject requests with a timestamp outside your allowed freshness window to reduce replay risk.

note

For 24 hours after rotation, we sign requests with both the previous and new secret. During this overlap, accept a valid signature from either secret.

Payload​

GET /1-click/health Response Body
{
event: "1-click.health.lookup",
healthDataUuid: string,
externalReference?: string,
sentAt: integer,
...1ClickHealthEntity
}
PropertyTypeFormatDescriptionExample
eventstring-Response from the 1-Click Health lookup"1-click.health.lookup"
healthDataUuidstringVersion 4 UUIDUnique identifier for the 1ClickHealthEntity that will be returned at the end of the 1-Click Health flow"9e12fe5b-5bb8-410a-ac6b-6e053e4c7e8d"
externalReferencestring1–256 charactersOptional customer identifier echoed unchanged from the POST /1-click/health request; not a lookup key"appointment-1042"
sentAtintegerUnix time (milliseconds)When the payload was sent1760053705000
...1ClickHealthEntitySee 1ClickHealthEntity1ClickHealthEntity for the 1-Click Health flowSee 1ClickHealthEntity

Webhook payloads are delivered at least once. The same event may be delivered more than once, including during retries, so deduplicate using healthDataUuid as the idempotency key. The externalReference is for correlating the result with your own record: it can't be used to retrieve the result.

Webhooks for 1-Click Signup are Coming Soon!

We don't yet support webhooks for 1-Click Signup, but those are coming soon. If you'd like to be notified when they're available, please email us at Support@Verified.inc.