Skip to content

API

Webhooks

Signed callbacks when a request completes, fails or flags a critical finding.

Add a webhook to the submit body, or register endpoints in Settings → Webhooks. MedRun POSTs the request object when subscribed events happen.

Events

request.started, request.stage (opt-in), request.succeeded, request.failed, request.canceled, request.rejected, upload.completed, credits.low.

Signatures

Webhooks follow Standard Webhooks: the headers webhook-id, webhook-timestamp and webhook-signature sign id.timestamp.body with HMAC-SHA256 (whsec_ secrets). During a secret rotation two signatures are sent.

Delivery

  • 15-second timeout; any 2xx counts as delivered.
  • Retries with exponential backoff and jitter for 24 hours.
  • A 410 response disables the endpoint.
  • Order is not guaranteed: deduplicate on webhook-id.
  • Every delivery is listed in Settings → Webhooks, where you can redeliver it.

The payload carries no patient identifiers; artifact links need authentication.