https:// webhook_url on your api_credentials.
Visit- and notification-status events include an
event_id that is stable
across retries; use it to deduplicate. Auto-book completion does not currently
include event_id, so make those handlers idempotent on
auto_book_request.id and its terminal status. occurred_at is reused on
retry. Delivery is at least once. Ordering is not guaranteed — a
booked event can arrive after canceled if the first delivery was delayed.
visits[].status on a subsequent GET is the source of truth.
Scan retries each subscriber up to five times with exponential backoff, 5s
connect / 15s read timeout. After five failures the delivery is marked failed. There
is no automatic replay after an extended outage; use
test events or GET the referral.
Verify the signature
X-Scan-Signature is v1=<hex> or v1=<hex>,v1=<hex> during secret rotation.
Compute HMAC-SHA256 of #{timestamp}.#{raw_body} with your signing secret.
referrals_notifications_webhook capability.
