Status changed
Scan.com sends an HTTP POST to the webhook_url on your api_credentials record when a
visit status changes. Your endpoint must accept JSON and return HTTP 2xx.
Request headers
| Header | Value |
|---|---|
| Content-Type | application/json |
| User-Agent | Scan.com-Webhook/1.0 |
| X-Scan-Event | visit.status_changed |
| X-Scan-Timestamp | Unix timestamp used in the signature |
| X-Scan-Signature | v1= followed by the HMAC-SHA256 digest |
Verify the signature by computing HMAC-SHA256 with your signing secret
over "{timestamp}.{raw_body}", using the exact request bytes.
Body
JSON POST body sent to your webhook_url
Stable event identifier reused for every delivery retry
Webhook event identifier
visit.status_changed "visit.status_changed"
Visit status after the change. Fires on every status change, not only post-scan ones. Each value is defined in the Track referral status guide.
pending, pending_auth, co_signed, intake_sent, ready_to_book, contacted_for_booking, booked, complete, exam_not_completed, sent_to_rad, report_uploaded, qc_report_ready, invoice_ready, sent_to_rp, canceled "booked"
Fields that changed on this event
Visit that changed
"11111111-1111-1111-1111-111111111111"
When the status change was committed (ISO 8601)
"2026-05-28T18:00:00Z"
Referral snapshot (same shape as GET /api/v2/referrals/{id})
Response
Your endpoint acknowledged the event

