Integration Fabric

Webhooks

HMAC-signed, versioned, and retried with exponential backoff.

Webhooks

Matches the outbound webhook design already specified in the Ecosystem Blueprint (Section 1.4.3) exactly — this page documents that design for partner consumption, it does not define a new one.

Signing

Every webhook payload is signed with HMAC-SHA256 using a shared secret issued at onboarding, rotatable on request.

X-Ensure-Signature: sha256=<hmac of raw payload body> X-Ensure-Event-Version: 1

Verify the signature before processing any payload. An unsigned or incorrectly-signed request should be rejected, not silently accepted.

Delivery & Retries

A failed delivery is retried on this schedule: 1s, 5s, 25s, 125s, then hourly for 24 hours. After 24 hours, the event moves to a dead-letter state and is available via the partner dashboard's event log for manual replay.

Versioning

The X-Ensure-Event-Version header changes only on a breaking schema change. Additive fields (new, optional) ship without a version bump — your integration should ignore unrecognized fields rather than fail on them.

Available Events (Phase 1)

Event Fires When
eligibility.updated A member's coverage status changes
formulary.check.completed A real-time NCPDP D.0 transaction your system responded to has been processed
escalation.routed A case involving your integration was routed for clinician/pharmacist review