visit.created
A visit is created: an invitation or pre-registration (from the API, the console or the Workspace app), a
walk-in at the kiosk, or a confirmed in-person booking. data.object.source tells you which.
Agoo sends this as a signed POST to every enabled endpoint subscribed to visit.created (or *). Verify the
signature, return any 2xx within 15 seconds, and de-duplicate on webhook-id.
Header Parameters
The event's ID. It is the same on every attempt and redelivery, so use it to de-duplicate.
^evt_[0-7][0-9a-hjkmnp-tv-z]{25}$"evt_01m4ww0ezgf2bryg9gxb2gbewx"When this attempt was signed, in Unix seconds. Reject the request if it is more than 5 minutes from your clock.
^[0-9]+$One or more space-separated signatures, each v1,<base64>: the base64 HMAC-SHA256 of
{webhook-id}.{webhook-timestamp}.{raw body}, keyed with the base64-decoded part of your whsec_ secret.
During a secret rotation there are two. Accept the request if any one matches.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
An event about a visit.
Response Body
Example Requests
/visit.createdRedeliver an event POST
Queues the event for delivery again, to one endpoint or to every enabled endpoint subscribed to its type. Redeliveries carry the same `webhook-id` as the original, so handlers that de-duplicate on it stay safe, and are retried on the usual schedule. Use it after fixing an endpoint that missed events. - An `endpoint_id` must be enabled and subscribed to the event's type (`validation_failed` otherwise). **Scope:** `webhooks:manage` · **Plan:** Growth, Pro and Enterprise in live mode; every plan in test mode.
visit.updated Webhook
A visit's details change: site, host, type, times, purpose or custom fields. Status changes fire their own events instead. Agoo sends this as a signed `POST` to every enabled endpoint subscribed to `visit.updated` (or `*`). Verify the signature, return any `2xx` within 15 seconds, and de-duplicate on `webhook-id`.