Skip to main content

webhooks

The link token m2_generate_link_token generated, or why it failed

Hosted by your bridge, not by ABDM. The gateway calls this endpoint at the callback URL registered for your bridge, so the path above is relative to that URL.

POST/v3/hip/token/on-generate-token

response.requestId echoes the REQUEST-ID you sent to m2_generate_link_token, so match this callback to that call before reading abhaAddress or linkToken.

Authorizations

Authorizationbearer tokenRequired

The accessToken from POST /api/hiecm/gateway/v3/sessions. Send it as Authorization: Bearer <ACCESS_TOKEN>. M2 also uses per flow tokens, a link token for linking and an authorisation token for patient scoped calls. Their header names are not yet published.

Headers

REQUEST-IDstringRequired

A fresh UUID that you generate for this request. The callback that answers it carries the same value, so this is how you match an asynchronous reply to the call that caused it. Store it before you send the request, not after.

TIMESTAMPstringRequired

The current time in ISO 8601, UTC, with milliseconds and a Z suffix, from a synchronised clock. The sandbox rejects IST and accepts UTC.

X-HIP-IDstringRequired

Identifier of the Health Information Provider the request or callback belongs to. This is per facility, and it is what a callback arriving at your one bridge URL is routed on. The bridge URL and your credentials belong to the integration, not to the facility.

Body

abhaAddressstring

Present on success.

linkTokenstring

The generated link token, present on success. Pass it as X-Link-Token on the next m2_hip_link_care_context call.

errorobject

The error code and message on a failed callback delivery.

error.codestringRequired
error.messagestringRequired
responseobjectRequired

Echo of the requestId from the original Gateway-to-HIP request

response.requestIdstringRequired

requestId received in the original Gateway request to HIP bridge

Responses

200

Your bridge accepted the callback. The gateway validates the body you send back, so a 200 carrying the wrong body is still a failure.

Where this fits

You produce this callback by calling Generate Link Token.