DEVELOPER GUIDE / REGISTRATION WEBHOOKS
01 · Event
A guest registration changes.
02 · Monday
Match the update to its Monday booking using the stable registration and booking IDs.
03 · Review
Review guest details and handle SIBA inside EazyAL.
Webhook events include registration status and counts, never guest names, contact details, nationalities or identity documents.
GET STARTED
01 · Create a fresh Make API key
In Make, create a Custom webhook with API-key authentication. Generate a fresh key (do not reuse the one sent by email), then copy the URL and key. Use hook.eu1.make.com, hook.eu2.make.com, hook.us1.make.com or hook.us2.make.com.
02 · Add the webhook in EazyAL
Open Casa Oakdene → Property settings → Integrations → Add webhook, choose Make, and paste the webhook URL and the new Make key.
03 · Save EazyAL’s signing secret
After saving, EazyAL shows the signing secret once. Copy it to a protected secret store; it is separate from the Make API key.
04 · Send a test event
Press Send test event and confirm the webhook.test event arrives in your Make scenario. Set the scenario to process requests sequentially.
1 / EVENT
Useful fields to map
event_id — stable event ID; retries reuse it.
data.checkin_session_id — stable identity for the guest registration.
data.external_booking_ref — Monday booking ID carried on the guest link.
data.status — current registration state (for example, ready_for_review); data.revision increases for each registration.
data.guests — expected, completed, SIBA-required and accepted counts.
data.blocker_codes and sendable_now — why a registration is waiting or ready.
{
"schema_version": 1,
"event_id": "11111111-1111-4111-8111-111111111111",
"type": "registration.updated",
"occurred_at": "2026-10-02T10:00:00Z",
"data": {
"checkin_session_id": "33333333-3333-4333-8333-333333333333",
"external_booking_ref": "CO-123323211",
"revision": 3,
"status": "ready_for_review",
"guests": { "expected": 2, "completed": 2 },
"sendable_now": false,
"blocker_codes": ["stay_unlinked"]
}
}
A registration.updated event contains IDs, status, counts and blockers, never guest names, contact details, nationalities or document details.
2 / AUTHENTICATION
Verify the signature
Standard Webhooks libraries can verify the raw signed content `<webhook-id>.<webhook-timestamp>.<raw body>` using the full `whsec_...` secret. For manual HMAC verification, remove the prefix and base64-decode the remainder.
Read webhook-id, webhook-timestamp and webhook-signature. Reject timestamps more than five minutes old.
Keep both keys private
The EazyAL signing secret appears once and is different from the Make API key. Keep both out of Monday columns and unprotected scenario history; use protected credential storage or a small server-side relay.
05 / GUEST LINK
One-line guest URL
https://app.eazyal.com/guestViewPageExternal?publicToken=<the property's link token>&session=<a random ID saved on the Monday item>&guests=<party size>&external_booking_ref=<Monday booking ID>
Use the property’s guest-link token as publicToken.
Save the generated session ID to the Monday item before sending the link.
Reuse one session ID for every guest on the booking. Keep all query parameters on this single URL line.
Match registration events to Monday
{
"data.external_booking_ref": "CO-123323211",
"data.checkin_session_id": "33333333-3333-4333-8333-333333333333",
"data.status": "ready_for_review",
}
Store checkin_session_id → Monday item ID and the last applied revision. Process requests sequentially; ignore duplicate or older revisions. Route missing or multiple booking matches to an error path.
PRIVACY AND WORKFLOW
Monday is not the guest record
Monday stores booking and registration IDs for matching. Guest identity and documents remain available only in EazyAL to users with property access.
EazyAL keeps the review gate
Make can keep Monday current, but an authorized host or operator reviews guest records and handles SIBA inside EazyAL.
Rotate credentials safely
Replace the EazyAL signing secret in webhook settings if it is exposed. To rotate Make’s API key, delete and recreate that webhook with the new key.
SCOPE AND DELIVERY
When events are sent
Events update as guests register, stays are linked, party sizes are confirmed, SIBA progresses, registrations are cancelled or an arrival becomes sendable. Payloads contain no guest PII.
Retries, duplicates and revisions
Delivery is at least once. Transient failures retry with backoff for up to 24 hours; duplicate deliveries keep the same event_id. Newer revisions supersede older undelivered updates. Save the last applied revision per checkin_session_id.
Use event_id to deduplicate, checkin_session_id as the registration key, and external_booking_ref to find the Monday item. Never match by guest name or stay dates.