attendance.late
A clock-in is later than the person's shift start plus its grace period. It fires after
attendance.clocked_in for the same clock-in; late_minutes says how late.
Agoo sends this as a signed POST to every enabled endpoint subscribed to attendance.late (or *). Verify the
signature, return any 2xx within 15 seconds, and de-duplicate on webhook-id.
Header Parameters
The event's ID. It is the same on every attempt and redelivery, so use it to de-duplicate.
^evt_[0-7][0-9a-hjkmnp-tv-z]{25}$"evt_01m4ww0ezgf2bryg9gxb2gbewx"When this attempt was signed, in Unix seconds. Reject the request if it is more than 5 minutes from your clock.
^[0-9]+$One or more space-separated signatures, each v1,<base64>: the base64 HMAC-SHA256 of
{webhook-id}.{webhook-timestamp}.{raw body}, keyed with the base64-decoded part of your whsec_ secret.
During a secret rotation there are two. Accept the request if any one matches.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
An event about a clock-in or clock-out.
Response Body
Example Requests
/attendance.lateattendance.clocked_out Webhook
An employee clocks out, by any method. Agoo sends this as a signed `POST` to every enabled endpoint subscribed to `attendance.clocked_out` (or `*`). Verify the signature, return any `2xx` within 15 seconds, and de-duplicate on `webhook-id`.
watchlist.matched Webhook
Someone checking in matches a watchlist entry. Agoo holds the check-in and alerts your security team silently at the same time; the visitor isn't told. Kiosks also screen while offline. A check-in a kiosk made offline is screened again when it syncs: if Agoo finds a match the kiosk's list didn't have, the visitor is already inside, and the event carries `entered_while_offline: true`. Agoo sends this as a signed `POST` to every enabled endpoint that lists `watchlist.matched` (`*` doesn't cover it). Verify the signature, return any `2xx` within 15 seconds, and de-duplicate on `webhook-id`.