UDI Lens

Events

Every event shares the same envelope:

FieldTypeDescription
typestringEvent type
api_versionstringSpec version, currently 2026-10-01
idstringEvent ID, same as the webhook-id header; sorts lexicographically
created_atstringWhen the event was created (ISO 8601, UTC)
dataobjectDepends on the event type

scan.created

An App user completed a scan.

{
  "type": "scan.created",
  "api_version": "2026-10-01",
  "id": "evt_01JB8Z3K9Q4C7XR2M5N6P8T0VW",
  "created_at": "2026-10-02T00:00:01.123Z",
  "data": {
    "scan_id": "5f0c2c1e-3b0a-4c39-9d0c-2f1d8f6b7a11",
    "scanned_at": "2026-10-02T07:59:58+08:00",
    "issuer": "GS1",
    "format": "gs1_element_string",
    "raw": "]d2010081234567890117270531",
    "di": "00812345678901",
    "lot": "A123",
    "serial": "S0001",
    "expiry": "2027-05-31",
    "production_date": null,
    "gudid": {
      "status": "found",
      "brand_name": "Sample Device",
      "company_name": "Sample Medical Inc.",
      "model_number": "SD-100"
    },
    "batch_id": null,
    "source": {
      "org_id": "org_8x2k4m9q0r1s3t5v7w",
      "member_id": "mem_2b4d6f8h0j2k4m6n8p",
      "member_label": "3F OR iPhone 2"
    }
  }
}

data fields

FieldTypeDescription
scan_iduuidScan ID generated by the App; unique per user
scanned_atdate-timeScan time on the device, with offset
issuerGS1 / HIBCCIssuing agency
formatstringgs1_element_string, gs1_digital_link, hibcc
rawstringRaw barcode content; GS1 FNC1 appears as ASCII 29; merged primary and secondary barcodes are joined with \n
distringDevice identifier; a 14-digit GTIN for GS1
lotstring or nullLot (AI 10)
serialstring or nullSerial (AI 21)
expirydate or nullExpiry (AI 17); day 00 is converted to the last day of the month
production_datedate or nullProduction date (AI 11)
gudidobject or nullFDA AccessGUDID lookup done on the device; status is found, not_found or unknown
batch_iduuid or nullBatch ID for batch scanning
sourceobjectSender: org_id (null in personal mode), member_id (mem_... in an organization, sub_... in personal mode; treat as opaque), member_label (set by an organization admin)

endpoint.verification

Sent when someone taps Verify after creating or changing the URL. Reply 200 with:

{ "challenge": "the same string as data.challenge" }

endpoint.test

Sent when someone taps Send test event. data is a sample scan in the same shape as scan.created. Run it through your normal pipeline, but don't store it as production data.

Compatibility

  • Within an api_version, we only add fields or event types. Ignore fields and type values you don't recognize.
  • Breaking changes ship as a new api_version, announced in advance (see the changelog).

The full OpenAPI 3.1 spec: openapi.yaml, or the interactive API reference.