Skip to main content
Every change to a referral creates an event. There are three ways to receive events: To get events for a single referral, register a per-referral webhook with its own token and expiry (POST /referrals/{id}/webhooks).

Verify signatures

Deliveries follow Standard Webhooks. Each one carries webhook-id, webhook-timestamp and webhook-signature headers. Verify them with the secret returned when you registered the endpoint.
Retries reuse the same webhook-id, so deduplicate on it.

Event types