Mobile-ID Digital TrustISO/IEC 27001:2022 · SIS351224I008Published certification scope
View evidence

DEVELOPER

Webhooks

Deliver partner callbacks with endpoint ownership, signed requests, bounded retry, replay support and idempotent consumption.

01 / CONCEPT

Integration contract

01

Registration

Register HTTPS endpoint, event subscription and responsible owner.

02

Signature

Verify signature and timestamp before parsing the event body; rotate signing material through a controlled lifecycle.

03

Delivery

Acknowledge quickly, process asynchronously and deduplicate by event identifier.

04

Failure

Expect retries, duplicates and possible out-of-order delivery; replay is an operational action with evidence.

02 / WORKFLOW

From sandbox to evidence

  1. 01Register endpoint/subscription
  2. 02Receive signed event
  3. 03Verify timestamp/signature
  4. 04Acknowledge delivery
  5. 05Deduplicate and process asynchronously
  6. 06Retry/replay on recoverable failure
  7. 07Correlate result
03 / EXAMPLE

Receive alert webhook

cURL / pseudocode
verifySignature(rawBody, signature, timestamp);
if (seen(event.id)) return 204;
enqueue(event); return 204;
04 / SECURITY & PRODUCTION

Production is an evidence decision

Webhook consumers must verify signatures, deduplicate, tolerate retry/out-of-order delivery and keep processing asynchronous before production approval.

Screen detail

Search all Trusted Care
TRUSTED CARE

09 applications

Governed application access; no unverified login URL is invented.

Patient AppPatients & familiesRequest accessDoctor PortalDoctors & cliniciansRequest accessNurse & Care CoordinatorNurses & care coordinatorsRequest accessAdmin PortalOrganization administratorsRequest accessHealth KioskReception & service pointsRequest accessPharmacy PortalPharmacistsRequest accessLaboratory PortalLaboratory teamsRequest accessCareGiver AppCaregivers & familiesRequest accessTelehealthPatients & care teamsRequest access