Skip to main content

Events & webhooks

The Events API lets you subscribe to changes such as case.status_changed or application.submitted. Deliveries are HTTPS POSTs signed with HMAC-SHA256 so you can verify they came from the agency platform.

Verify a delivery
import hmac, hashlib

def verify(secret: bytes, body: bytes, header: str) -> bool:
    # header: "t=1791039600,v1=5f2b..."
    parts = dict(p.split("=", 1) for p in header.split(","))
    signed = f"{parts['t']}.".encode() + body
    expected = hmac.new(secret, signed, hashlib.sha256).hexdigest()
    return hmac.compare_digest(expected, parts["v1"])
  • Respond 2xx within 10 seconds; do slow work asynchronously.
  • Deliveries are at least once. De-duplicate on eventId.
  • Reject deliveries older than five minutes to prevent replay.
  • Use the replay operation to recover missed events after an outage.