What webhooks are
CaseXchange pushes referral lifecycle events to an HTTPS endpoint you control. Instead of pollingGET /sent-cases or GET /received-referrals on a timer to notice that something changed, you register a URL once and CaseXchange sends an HTTPS POST to it each time an event happens for your firm.
Webhooks are a signal to reconcile, not a sync feed: the read endpoints (GET /status-updates, GET /referrals, GET /sent-cases, GET /received-referrals) remain the authority, and a subscription only receives events that happen after it is created — there is no backfill and no replay.
What you receive
Every active subscription receives every event for your firm. There is no per-subscription filter, so branch on the event name (theevent field in the body, also sent as the X-CaseXchange-Event header) and ignore names you do not handle.
A receiving firm gets
case.updated and the sending firm’s notes only once it has acknowledged the referral and while the referral is in a working status — which still includes closed. document.* is stricter: document access also ends at closed. Notes its own firm wrote always reach it, acknowledged or not. See Client data and masking.
The Event catalog has the envelope, the data shape and the recipient rules for each event.
What you can rely on
Before you start
You need three things:
Subscriptions are created and managed through the API only —
POST /webhooks, PATCH /webhooks/{id}, DELETE /webhooks/{id} and the other endpoints on the Managing subscriptions page. There is no dashboard page for firm webhooks.
Provider (Med Xchange) keys manage their own subscriptions through the same endpoints with a different payload. This tab documents firm webhooks only.
Where to go next
Webhooks quickstart
Create a subscription, send a test delivery and verify your first signature.
Managing subscriptions
Create, list, update, rotate, deactivate and delete subscriptions, and the limits that apply.
Anatomy of a delivery
The headers, the envelope fields and how to deduplicate and order what arrives.
Event catalog
The envelope, every event, its
data shape and who receives it.Verifying signatures
Check
X-CaseXchange-Signature before you trust a body; rotate secrets safely.Reliability
Retries, delivery statuses, automatic deactivation of a failing endpoint, and retention.
Testing webhooks
Test deliveries, echo mode and local development without a public endpoint.
Client data and masking
What a masked snapshot contains, what unmasks it and what each side is entitled to see.
Troubleshooting
Error codes,
lastError values and what to do about them.Known gaps
Actions that deliberately produce no event, so you know what to reconcile instead.

