Skip to main content

Webhooks Management

Web dashboard only — not accessible via API key

Webhooks are created and configured exclusively from the MonCréneau web dashboard, by a STAFF user (ADMIN or OWNER role) authenticated via a session.

A third-party external application cannot call these endpoints. They are authenticated by session cookie (web login), not by API key (X-API-Key) — there is no way for an external integrator to obtain this session programmatically. This page describes the behavior for reference, not as an integration you can build from your own code.

Required access​

  • Authenticated session via the web interface (session cookie)
  • ADMIN or OWNER role

List webhooks​

GET /api/staff/webhooks — called by the dashboard to display configured webhooks.

200 response:

{
"id": 123,
"url": "https://your-app.com/webhooks/moncreneau",
"events": ["APPOINTMENT_CREATED", "APPOINTMENT_CANCELLED"],
"isActive": true,
"createdAt": "2026-01-10T12:00:00",
"lastTriggeredAt": "2026-01-22T09:15:00",
"healthStatus": "HEALTHY"
}

The HMAC secret is never returned by this endpoint (nor by any other after creation) — see Webhook Security.

Create a webhook​

POST /api/staff/webhooks — { "url": "...", "events": ["APPOINTMENT_CREATED"] }.

The HMAC secret is generated server-side on creation (you never provide it) — it's only visible once, in the creation response. Save it immediately.

Update a webhook​

PATCH /api/staff/webhooks/{id} — { "url"?: "...", "events"?: [...], "isActive"?: true } (all fields optional, only the ones provided are updated).

Delete a webhook​

DELETE /api/staff/webhooks/{id}

Test a webhook​

POST /api/staff/webhooks/{id}/test — sends a signed test event to the webhook and returns the result (the remote response body is never returned, for security reasons).

History and retry​

GET /api/staff/webhooks/{id}/logs — paginated delivery attempt history. POST /api/staff/webhooks/logs/{logId}/retry — retries a failed delivery.

Available events​

  • APPOINTMENT_CREATED — a new appointment was created
  • APPOINTMENT_UPDATED — an appointment was modified
  • APPOINTMENT_CANCELLED — an appointment was cancelled
  • APPOINTMENT_COMPLETED — an appointment was marked completed
  • APPOINTMENT_NO_SHOW — the user did not show up
  • SLOT_AVAILABILITY_CHANGED — a slot's availability changed

See Webhook Events for payload details.