booking.confirmed
The host confirms a pending booking: in the console, in the Workspace app, from the link in their
confirmation request, or through the API. Bookings that don't need confirmation fire only
booking.created, with status: confirmed. In-person bookings also fire visit.created for the visit
created now.
Agoo sends this as a signed POST to every enabled endpoint subscribed to booking.confirmed (or *). Verify the
signature, return any 2xx within 15 seconds, and de-duplicate on webhook-id.
Header Parameters
The event's ID. It is the same on every attempt and redelivery, so use it to de-duplicate.
^evt_[0-7][0-9a-hjkmnp-tv-z]{25}$"evt_01m4ww0ezgf2bryg9gxb2gbewx"When this attempt was signed, in Unix seconds. Reject the request if it is more than 5 minutes from your clock.
^[0-9]+$One or more space-separated signatures, each v1,<base64>: the base64 HMAC-SHA256 of
{webhook-id}.{webhook-timestamp}.{raw body}, keyed with the base64-decoded part of your whsec_ secret.
During a secret rotation there are two. Accept the request if any one matches.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
An event about a booking.
Response Body
Example Requests
/booking.confirmedbooking.created Webhook
Someone books a slot, on a booking page, in an embed or through the API. It fires for every booking: `status` is `pending` when the booking type requires host confirmation, and `confirmed` otherwise. Confirmed in-person bookings also fire `visit.created` for the linked visit. Agoo sends this as a signed `POST` to every enabled endpoint subscribed to `booking.created` (or `*`). Verify the signature, return any `2xx` within 15 seconds, and de-duplicate on `webhook-id`.
booking.declined Webhook
The host declines a `pending` booking. The slot is free again, and the attendee is told their request wasn't accepted. `decline_reason` is for your organisation; the attendee sees it only if the host chose to share it. Agoo sends this as a signed `POST` to every enabled endpoint subscribed to `booking.declined` (or `*`). Verify the signature, return any `2xx` within 15 seconds, and de-duplicate on `webhook-id`.