openevidence-webhooks-events
Configures and verifies webhooks for OpenEvidence to receive notifications about query completion and clinical updates.
Install
mkdir -p .claude/skills/openevidence-webhooks-events && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/5398" && unzip -o skill.zip -d .claude/skills/openevidence-webhooks-events && rm skill.zipInstalls to .claude/skills/openevidence-webhooks-events
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Webhooks Events for OpenEvidence.Key capabilities
- →Subscribe to clinical events like query completion
- →Verify webhook signatures for security
- →Handle asynchronous notifications for evidence updates
- →Implement idempotent event processing
How it works
The skill registers webhooks to receive asynchronous notifications and provides a signature verification mechanism to ensure event authenticity before processing.
Inputs & outputs
When to use openevidence-webhooks-events
- →Subscribe to clinical events
- →Verify webhook signatures
- →Build event-driven AI workflows
- →Manage query notifications
About this skill
OpenEvidence Webhooks & Events
Overview
OpenEvidence delivers webhook notifications for clinical evidence retrieval workflows. Subscribe to events when queries complete, evidence bases are updated, new citations are added, or clinical reviews are flagged. Use these webhooks to keep clinical decision support systems current and trigger downstream audit workflows in real time.
Webhook Registration
const response = await fetch("https://api.openevidence.com/v1/webhooks", {
method: "POST",
headers: {
"Authorization": `Bearer ${process.env.OPENEVIDENCE_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
url: "https://yourapp.com/webhooks/openevidence",
events: ["query.completed", "evidence.updated", "citation.added", "review.flagged"],
secret: process.env.OPENEVIDENCE_WEBHOOK_SECRET,
}),
});
Signature Verification
import crypto from "crypto";
import { Request, Response, NextFunction } from "express";
function verifyOpenEvidenceSignature(req: Request, res: Response, next: NextFunction) {
const signature = req.headers["x-openevidence-signature"] as string;
const expected = crypto.createHmac("sha256", process.env.OPENEVIDENCE_WEBHOOK_SECRET!)
.update(req.body).digest("hex");
if (!crypto.timingSafeEqual(Buffer.from(signature), Buffer.from(expected))) {
return res.status(401).json({ error: "Invalid signature" });
}
next();
}
Event Handler
import express from "express";
const app = express();
app.post("/webhooks/openevidence", express.raw({ type: "application/json" }), verifyOpenEvidenceSignature, (req, res) => {
const event = JSON.parse(req.body.toString());
res.status(200).json({ received: true });
switch (event.type) {
case "query.completed":
deliverResults(event.data.query_id, event.data.evidence_count); break;
case "evidence.updated":
refreshClinicalCache(event.data.topic_id, event.data.revision); break;
case "citation.added":
indexCitation(event.data.citation_id, event.data.pubmed_id); break;
case "review.flagged":
escalateReview(event.data.review_id, event.data.flag_reason); break;
}
});
Event Types
| Event | Payload Fields | Use Case |
|---|---|---|
query.completed | query_id, evidence_count, confidence | Deliver clinical answers to requester |
evidence.updated | topic_id, revision, sources_changed | Refresh cached evidence summaries |
citation.added | citation_id, pubmed_id, journal | Index new literature into knowledge base |
review.flagged | review_id, flag_reason, severity | Escalate flagged content for human review |
query.failed | query_id, error_code, retry_after | Alert ops and queue retry |
Retry & Idempotency
const processed = new Set<string>();
async function handleIdempotent(event: { id: string; type: string; data: any }) {
if (processed.has(event.id)) return;
await routeEvent(event);
processed.add(event.id);
if (processed.size > 10_000) {
const entries = Array.from(processed);
entries.slice(0, entries.length - 10_000).forEach((id) => processed.delete(id));
}
}
Error Handling
| Issue | Cause | Fix |
|---|---|---|
| Signature mismatch | Secret rotation during deployment | Re-sync secret from OpenEvidence dashboard |
Empty evidence_count | Query matched no indexed sources | Check query scope and topic coverage |
Stale pubmed_id | Citation retracted after indexing | Subscribe to citation.retracted events |
| Review escalation loop | Automated re-flag on same content | Deduplicate by review_id with cooldown |
Resources
Next Steps
See openevidence-security-basics.
Prerequisites
Limitations
- →Signature mismatch if secret is rotated without re-sync
How it compares
It uses HMAC signature verification to secure event-driven clinical workflows, ensuring that only authenticated notifications trigger downstream actions.
Compared to similar skills
openevidence-webhooks-events side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| openevidence-webhooks-events (this skill) | 1 | 27d | Review | Intermediate |
| telegram-bot-builder | 106 | 6mo | Review | Intermediate |
| n8n-expression-syntax | 6 | 4mo | No flags | Beginner |
| reddit-api | 3 | 4mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
telegram-bot-builder
davila7
Expert in building Telegram bots that solve real problems - from simple automation to complex AI-powered bots. Covers bot architecture, the Telegram Bot API, user experience, monetization strategies, and scaling bots to thousands of users. Use when: telegram bot, bot api, telegram automation, chat bot telegram, tg bot.
n8n-expression-syntax
czlonkowski
Validate n8n expression syntax and fix common errors. Use when writing n8n expressions, using {{}} syntax, accessing $json/$node variables, troubleshooting expression errors, or working with webhook data in workflows.
reddit-api
alinaqi
Reddit API with PRAW (Python) and Snoowrap (Node.js)
mcporter
openclaw
Use the mcporter CLI to list, configure, auth, and call MCP servers/tools directly (HTTP or stdio), including ad-hoc servers, config edits, and CLI/type generation.
calcom-api
calcom
Interact with the Cal.com API v2 to manage scheduling, bookings, event types, availability, and calendars. Use this skill when building integrations that need to create or manage bookings, check availability, configure event types, or sync calendars with Cal.com's scheduling infrastructure.
instantly-webhooks-events
jeremylongshore
Implement Instantly webhook signature validation and event handling. Use when setting up webhook endpoints, implementing signature verification, or handling Instantly event notifications securely. Trigger with phrases like "instantly webhook", "instantly events", "instantly webhook signature", "handle instantly events", "instantly notifications".