API
Webhooks
Signed callbacks when a request completes, fails or flags a critical finding.
Add a webhook to the submit body, or register endpoints in Settings → Webhooks. MedRun POSTs the request object when subscribed events happen.
Events
request.started, request.stage (opt-in), request.succeeded, request.failed, request.canceled, request.rejected, upload.completed, credits.low.
Signatures
Webhooks follow Standard Webhooks: the headers webhook-id, webhook-timestamp and webhook-signature sign id.timestamp.body with HMAC-SHA256 (whsec_ secrets). During a secret rotation two signatures are sent.
Delivery
- 15-second timeout; any 2xx counts as delivered.
- Retries with exponential backoff and jitter for 24 hours.
- A
410response disables the endpoint. - Order is not guaranteed: deduplicate on
webhook-id. - Every delivery is listed in Settings → Webhooks, where you can redeliver it.
The payload carries no patient identifiers; artifact links need authentication.