Webhook events for launch partners and planned integrations
Not generally available. These webhook events describe launch-partner and planned capability. NoteGate works standalone today, and no CRM connector is live. Contact info@notegate.com.au about launch-partner access.
NoteGate emits signed webhook events on compliance documentation lifecycle for regulated care providers under the Aged Care Act 2024 and NDIS Practice Standards. Additional events for CRM write-back and admin actions are coming with the launch partner program.
Events live today
Register a webhook endpoint via the admin dashboard. NoteGate will POST a signed JSON payload to your endpoint for each event. All events include a X-NoteGate-Signature header for verification.
Emitted when a worker completes the compliant note-taking workflow and the note is submitted. Payload includes the compliant note content, participant ID, shift ID, compliance result, and audit metadata.
Planned events
Emitted when the compliant note is successfully written to the originating CRM's notes record. Payload includes both the NoteGate note ID and the CRM-side note ID so you can reconcile the records.
Emitted when the outbound write to the CRM fails after all retry attempts. Payload includes the failure reason and retry status so your team can act before the note is lost.
Emitted when a tenant admin updates the field mapping override set via POST /v1/admin/mappings. Useful for audit logging in your own systems.
Verifying webhook signatures
All webhook payloads are signed with HMAC-SHA256 using a per-tenant secret. Verify the signature before processing any event.
Signature header
NoteGate sends the signature in the X-NoteGate-Signature header in the format sha256=<hex_digest>. The digest is computed over the raw request body using your tenant's webhook secret.
JavaScript verification example
Python verification example
Timestamp tolerance
Each payload includes a created_at ISO 8601 timestamp. Reject payloads where created_at is more than 5 minutes old to prevent replay attacks. NoteGate does not include a separate timestamp in the signature, so use created_at for freshness checks.
Retry policy
If your endpoint returns a non-2xx response, NoteGate retries with exponential backoff up to 5 attempts over 24 hours.
| Attempt | Delay |
|---|---|
| 1 | Immediate |
| 2 | 5 minutes |
| 3 | 30 minutes |
| 4 | 2 hours |
| 5 | 22 hours |
After 5 failed attempts, the event is moved to a dead-letter queue visible in your tenant admin dashboard. Dead-letter visibility is planned - contact api@notegate.com.au if you need a failed event replayed before then.
Register a webhook endpoint
Webhook endpoints are registered in your NoteGate tenant admin dashboard under Settings › Webhooks. Your endpoint must:
- Accept HTTPS POST requests
- Respond with a 2xx status within 10 seconds
- Process the event asynchronously if handling takes longer
To request sandbox access for webhook testing, email api@notegate.com.au with the subject "Webhook sandbox access".
Related launch-partner pages, which describe planned capability: the planned API and migrating existing documentation.
Start with NoteGate today.
Solo and Starter subscribe immediately. Growth and above start with a 14-day trial with a card saved.