Events & webhooks
The Events API lets you subscribe to changes such as case.status_changed or application.submitted. Deliveries are HTTPS POSTs signed with HMAC-SHA256 so you can verify they came from the agency platform.
Verify a delivery
import hmac, hashlib
def verify(secret: bytes, body: bytes, header: str) -> bool:
# header: "t=1791039600,v1=5f2b..."
parts = dict(p.split("=", 1) for p in header.split(","))
signed = f"{parts['t']}.".encode() + body
expected = hmac.new(secret, signed, hashlib.sha256).hexdigest()
return hmac.compare_digest(expected, parts["v1"])- Respond 2xx within 10 seconds; do slow work asynchronously.
- Deliveries are at least once. De-duplicate on
eventId. - Reject deliveries older than five minutes to prevent replay.
- Use the replay operation to recover missed events after an outage.