POST/api/v1/s2s/partners/pharmacies/{partnerOrgId}/webhooks
Create partner pharmacy webhook
Published Partner endpoint from the stable OpenAPI 1.0.0 contract.
Overview
Use this endpoint only with a Partner API key. Code samples use placeholders and the public sandbox URL.
- Method
- POST
- Endpoint
- /api/v1/s2s/partners/pharmacies/{partnerOrgId}/webhooks
- Authentication
- X-API-Key
Request
Parameters
- partnerOrgIdstring (uuid)pathRequired
- Partner-controlled pharmacy identifier from the registration call.
- Example: pharmacy-4711
- X-Correlation-IDstringheader
- Optional opaque request correlation ID for tracing API calls across systems. Billing audit paths persist only UUIDv4-shaped values and drop free-form values.
- Example: 33333333-3333-4333-8333-333333333333
Request body
Required- authobject
- Optional OAuth2 client-credentials configuration for receivers that expect bearer-authenticated deliveries instead of the default HMAC-signed mode. Omit entirely to keep HMAC signing.
- auth.clientIdstringRequired
- OAuth2 client identifier.
- Example: akflow-webhook-client
- auth.clientSecretstringRequired
- OAuth2 client secret. Write-only: accepted on creation, stored encrypted, and never included in any response.
- Example: <CLIENT_SECRET>
- auth.modestringRequired
- Fixed delivery auth mode discriminator.
- Example: OAUTH2_CLIENT_CREDENTIALS
- auth.scopestring
- Optional OAuth2 scope sent as the `scope` form parameter on the token request. Set it when the partner channel requires a specific scope value for webhook deliveries.
- Example: webhooks:deliver
- auth.tokenUrlstringRequired
- HTTPS token endpoint for the client-credentials grant. Subject to the same SSRF host restrictions as the webhook url.
- Example: https://auth.partner.example/oauth2/token
- eventsarrayRequired
- Subscribed partner events. This enum is derived from the authoritative ALLOWED_PARTNER_WEBHOOK_EVENTS constant (partner-webhooks.service.ts), so it cannot drift from the values the API actually accepts.
- Example: ["appointment.created","appointment.cancelled"]
- urlstringRequired
- HTTPS receiver URL. IP literals, localhost and cluster-internal hosts are rejected.
- Example: https://webhooks.partner.example/akflow
Contract
The versioned OpenAPI contract is the authoritative source for parameters, request bodies, and response schemas.
Version
1.0.0
Expected response
201 Created