Webhooks Management
Webhooks are created and configured exclusively from the MonCréneau web dashboard, by a STAFF user (ADMIN or OWNER role) authenticated via a session.
A third-party external application cannot call these endpoints. They are authenticated by session cookie (web login), not by API key (X-API-Key) — there is no way for an external integrator to obtain this session programmatically. This page describes the behavior for reference, not as an integration you can build from your own code.
Required access
- Authenticated session via the web interface (session cookie)
- ADMIN or OWNER role
List webhooks
GET /api/staff/webhooks — called by the dashboard to display configured webhooks.
200 response:
{
"id": 123,
"url": "https://your-app.com/webhooks/moncreneau",
"events": ["APPOINTMENT_CREATED", "APPOINTMENT_CANCELLED"],
"isActive": true,
"createdAt": "2026-01-10T12:00:00",
"lastTriggeredAt": "2026-01-22T09:15:00",
"healthStatus": "HEALTHY"
}
The HMAC secret is never returned by this endpoint (nor by any other after creation) — see Webhook Security.
Create a webhook
POST /api/staff/webhooks — { "url": "...", "events": ["APPOINTMENT_CREATED"] }.
The HMAC secret is generated server-side on creation (you never provide it) — it's only visible once, in the creation response. Save it immediately.
Update a webhook
PATCH /api/staff/webhooks/{id} — { "url"?: "...", "events"?: [...], "isActive"?: true } (all fields optional, only the ones provided are updated).
Delete a webhook
DELETE /api/staff/webhooks/{id}
Test a webhook
POST /api/staff/webhooks/{id}/test — sends a signed test event to the webhook and returns the result (the remote response body is never returned, for security reasons).
History and retry
GET /api/staff/webhooks/{id}/logs — paginated delivery attempt history.
POST /api/staff/webhooks/logs/{logId}/retry — retries a failed delivery.
Available events
APPOINTMENT_CREATED— a new appointment was createdAPPOINTMENT_UPDATED— an appointment was modifiedAPPOINTMENT_CANCELLED— an appointment was cancelledAPPOINTMENT_COMPLETED— an appointment was marked completedAPPOINTMENT_NO_SHOW— the user did not show upSLOT_AVAILABILITY_CHANGED— a slot's availability changed
See Webhook Events for payload details.