> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scan.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Notification status changed

> Sent when an email or SMS notification is created or its delivery status changes.
This event is metadata-only and never includes recipient details or message content.

Configure an HTTPS webhook URL and ask Scan to enable notification webhooks for
your account. Delivery is at least once; deduplicate using `event_id`.
Your endpoint must return HTTP 2xx.

**Request headers**

| Header | Value |
|--------|--------|
| Content-Type | application/json |
| User-Agent | Scan.com-Webhook/1.0 |
| X-Scan-Event | notification.status_changed |
| X-Scan-Timestamp | Unix timestamp used in the signature |
| X-Scan-Signature | `v1=` followed by the HMAC-SHA256 digest |

Verify the signature by computing HMAC-SHA256 with your signing secret
over `"{timestamp}.{raw_body}"`, using the exact request bytes.




## OpenAPI

````yaml openapi.yaml webhook notificationStatusChanged
openapi: 3.1.0
info:
  title: Scan.com API
  version: v2
  description: >
    This API provides comprehensive access to Scan.com’s core functionalities, 

    including management of referrals, patient information, authentication, body
    parts, 

    and imaging modalities. It enables seamless integration for scheduling, data
    retrieval, 

    and workflow automation within the Scan.com platform, facilitating efficient
    and secure 

    handling of medical imaging processes.
servers:
  - url: https://api.staging.scan.com
    description: Sandbox
  - url: https://api.scan.com
    description: Production
security:
  - BearerAuth: []
tags:
  - name: Courier SSO
    description: >-
      Mint a one-time Courier portal SSO URL with the same Bearer token used for
      the rest of the API.
  - name: Webhooks
    description: >-
      Outbound HTTP POST notifications sent to your api_credentials.webhook_url
      when visit or notification status changes. Configure api_credentials on
      your LawFirm, Practice, CoordinationGroup, Insurance, Employer, or
      NurseCaseManagementGroup.
  - name: Order Documents
    description: >-
      Retrieve radiology report PDFs, DICOM imaging, and invoices for orders
      visible to the authenticated group.
  - name: Locations
    description: >-
      Rank nearby imaging centers for a referral after medical safety answers
      are on file. Partners submit a preferred center; Scan books the visit.
  - name: Testing
    description: Staging-only fixture bootstrap, status advancement, and test webhooks.
  - name: FHIR
    description: >-
      Opt-in FHIR R4 read shapes for DiagnosticReport and ImagingStudy. Not a
      FHIR server.
paths: {}
components:
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >
        `Authorization: Bearer <api_token>`. Sandbox tokens come from Get API
        keys

        and allow 2,000 successful requests or 7 days. Failed 4xx/5xx responses
        do

        not consume the allowance. Production tokens are issued from the group's

        API access tab.

````