Skip to main content
Webhooks let your backend receive real-time notifications of what happens during calls.
Webhooks are not registered from the external API: they are configured in the platform (or with the Omniloy team) and attached to a protocol version. This page documents the events you will receive and how they are delivered.

Events

Payloads

The payload is built per event and includes the questionnaire and protocol context. Answers and transcriptions have the same shape the read endpoints return, so you can handle them with the same code wherever they came from. run.status_changed:
answers[] carries one entry per question the questionnaire reached, in the order the patient heard them: question.answered delivers that same entry for a single question, without the timestamps or call_id:
This event carries the value as it stood when it was captured, even if the question is answered again later. That is why it has no timestamps and no call_id: those live on a row that is rewritten on a re-answer, and reporting them here would pair one answer’s timing with another answer’s value. When you need the questionnaire’s full, self-consistent picture, read it with GET /v1/protocol-runs/{runId}.
Questions and options travel by key, never by internal identifier: keys are stable across versions and do not change if someone rewrites the wording.
Payloads do not include patient personal data unless the event explicitly requires it (e.g. number.to_verify, which carries patient_id and phone). To link a run to a patient, join on run.enrollment_id.

Authentication to your endpoint

OlivIA does not sign the body with HMAC. Instead, each webhook authenticates against your endpoint with the credentials you configure. Options: Secrets are encrypted at rest (AES-256-GCM) and shown masked. Protect your endpoint by validating these credentials.

Delivery and retries

  • Best-effort delivery; every attempt is recorded.
  • Configurable retries: max_retries (0–10) and timeout_ms (100–60000, default 10000).
  • Retried on network errors, timeouts, and 5xx responses. Not retried on 4xx. Redirects are not followed.