Skip to main content
POST
Register a webhook endpoint

Authorizations

Authorization
string
header
default:sk_test_DEMO0000_replace_with_your_sandbox_key
required

API key authentication. Issued by the Safariat admin or via the partner portal. The secret is shown only once at generation.

Production sk_live_* keys must additionally sign every write request (POST/PUT/DELETE) with the X-Timestamp and X-Signature headers. Sandbox sk_test_* keys are exempt from request signing: X-Signature and X-Timestamp are not required for writes in the sandbox (so the developer-portal "Try it" playground works end to end). The Idempotency-Key header remains required on writes in both environments.

Headers

Idempotency-Key
string
required

Opaque, client-generated string unique per logical operation (a UUID v4 is recommended but any non-blank value up to 255 chars is accepted). Same key + same body = the cached response is returned with the Idempotent-Replayed: true header. Same key + different body = 409 Conflict. Retained for 24 h.

Maximum string length: 255
X-Timestamp
integer<int64>
required

Unix timestamp in seconds at the time the request is issued. Validity window ±5 minutes — beyond that the request is rejected. Required for production sk_live_* keys only; not required for sandbox sk_test_* keys.

X-Signature
string
required

hex(HMAC_SHA256(secret, "{X-Timestamp}\n{METHOD}\n{path}\n{body}")). The path includes the query string. The body is the exact JSON representation sent — any reformatting invalidates the signature. Required for production sk_live_* keys only; not required for sandbox sk_test_* keys.

Pattern: ^[a-f0-9]{64}$

Body

application/json
url
string<uri>
required

The bank's HTTPS endpoint. HTTP is rejected.

Pattern: ^https://
events
enum<string>[]
required
Minimum array length: 1
Available options:
booking.confirmed,
booking.cancelled,
booking.completed,
settlement.issued,
settlement.paid,
review.moderated
description
string
Maximum string length: 200

Response

Webhook created, signing_secret returned in clear (once only)

id
string<uuid>
required
url
string<uri>
required
events
enum<string>[]
required
Available options:
booking.confirmed,
booking.cancelled,
booking.completed,
settlement.issued,
settlement.paid,
review.moderated
status
enum<string>
required
Available options:
ACTIVE,
DISABLED
created_at
string<date-time>
required
signing_secret
string
required

HMAC secret to verify X-SafarApi-Signature on deliveries. Shown only once, never displayable again.

description
string | null
last_delivery_at
string<date-time> | null
last_delivery_status
integer | null

Last HTTP status received from the bank.