Events
Every event shares the same envelope:
| Field | Type | Description |
|---|---|---|
type | string | Event type |
api_version | string | Spec version, currently 2026-10-01 |
id | string | Event ID, same as the webhook-id header; sorts lexicographically |
created_at | string | When the event was created (ISO 8601, UTC) |
data | object | Depends on the event type |
scan.created
An App user completed a scan.
{
"type": "scan.created",
"api_version": "2026-10-01",
"id": "evt_01JB8Z3K9Q4C7XR2M5N6P8T0VW",
"created_at": "2026-10-02T00:00:01.123Z",
"data": {
"scan_id": "5f0c2c1e-3b0a-4c39-9d0c-2f1d8f6b7a11",
"scanned_at": "2026-10-02T07:59:58+08:00",
"issuer": "GS1",
"format": "gs1_element_string",
"raw": "]d2010081234567890117270531",
"di": "00812345678901",
"lot": "A123",
"serial": "S0001",
"expiry": "2027-05-31",
"production_date": null,
"gudid": {
"status": "found",
"brand_name": "Sample Device",
"company_name": "Sample Medical Inc.",
"model_number": "SD-100"
},
"batch_id": null,
"source": {
"org_id": "org_8x2k4m9q0r1s3t5v7w",
"member_id": "mem_2b4d6f8h0j2k4m6n8p",
"member_label": "3F OR iPhone 2"
}
}
}
data fields
| Field | Type | Description |
|---|---|---|
scan_id | uuid | Scan ID generated by the App; unique per user |
scanned_at | date-time | Scan time on the device, with offset |
issuer | GS1 / HIBCC | Issuing agency |
format | string | gs1_element_string, gs1_digital_link, hibcc |
raw | string | Raw barcode content; GS1 FNC1 appears as ASCII 29; merged primary and secondary barcodes are joined with \n |
di | string | Device identifier; a 14-digit GTIN for GS1 |
lot | string or null | Lot (AI 10) |
serial | string or null | Serial (AI 21) |
expiry | date or null | Expiry (AI 17); day 00 is converted to the last day of the month |
production_date | date or null | Production date (AI 11) |
gudid | object or null | FDA AccessGUDID lookup done on the device; status is found, not_found or unknown |
batch_id | uuid or null | Batch ID for batch scanning |
source | object | Sender: org_id (null in personal mode), member_id (mem_... in an organization, sub_... in personal mode; treat as opaque), member_label (set by an organization admin) |
endpoint.verification
Sent when someone taps Verify after creating or changing the URL. Reply 200 with:
{ "challenge": "the same string as data.challenge" }
endpoint.test
Sent when someone taps Send test event. data is a sample scan in the same shape as scan.created. Run it through your normal pipeline, but don't store it as production data.
Compatibility
- Within an
api_version, we only add fields or event types. Ignore fields andtypevalues you don't recognize. - Breaking changes ship as a new
api_version, announced in advance (see the changelog).
The full OpenAPI 3.1 spec: openapi.yaml, or the interactive API reference.