Skip to main content
GraphQL and MCP let you write to Photon. Webhooks tell your backend what happens next: when an order reaches a pharmacy, when it’s ready or shipped, and when it’s picked up or delivered. Typical uses:
  • Text or email the patient when their order ships or is ready
  • Record sent prescriptions in your own chart
  • Follow up on orders that are canceled or hit an error
Drafts don’t send webhooks. Events start when an order is sent (state: SUBMITTED). The order keeps the ord_… id it had as a draft.

Subscribe

In the dashboard, open Settings → Developers and add a webhook:
  • URL: an HTTPS endpoint on your backend
  • Events: all events, or only the types you choose
  • Shared secret: used to sign every request. Always set one.

The request

Photon sends one POST per event. The body is a JSON CloudEvent:

Verify the signature

Compute the HMAC-SHA256 of the raw request body with your shared secret, and compare it with X-Photon-Signature. Reject the request if they don’t match.
Node.js (Express)
Hash the body before you parse it. Re-serializing parsed JSON can change the bytes and break the match. The content type isn’t application/json, so make sure your framework gives you the raw body.

Responses and retries

Return 2xx for events you don’t use, too. Return 2xx as soon as you’ve stored the event, and do slow work afterward.

Handling events

  • Expect duplicates. The same event can arrive more than once. Make your handler idempotent, for example by recording each event id you’ve processed.
  • Expect any order. Events aren’t guaranteed to arrive in the order they happened. Compare time to tell which is latest.

Status: Network first, webhooks for progress

The status a Network API call returns is the source of truth: Once an order is SUBMITTED, webhooks report its progress through fulfillment. Expect these events, in this order: At any point, an order can also be order:rerouted (then order:placed again at the new pharmacy), order:canceled, or hit an order:error. See Events.