DEVELOPER GUIDE / REGISTRATION WEBHOOKS

Keep EazyAL registrations in sync with your team’s tools.

Keep EazyAL registrations in sync with your team’s tools.

EazyAL sends signed registration updates to Make, Monday.com or another HTTPS endpoint. Guest details, review and SIBA submission stay in EazyAL.

EazyAL sends signed registration updates to Make, Monday.com or another HTTPS endpoint. Guest details, review and SIBA submission stay in EazyAL.

01 · Event

A guest registration changes.

02 · Monday

Match the update to its Monday booking using the stable registration and booking IDs.

03 · Review

Review guest details and handle SIBA inside EazyAL.

Webhook events include registration status and counts, never guest names, contact details, nationalities or identity documents.

GET STARTED

Set up Make in five steps

Set up Make in five steps

Webhooks require a paid plan and belong to a property. Make uses a fresh API key for delivery; EazyAL creates a separate signing secret for verification.

Webhooks require a paid plan and belong to a property. Make uses a fresh API key for delivery; EazyAL creates a separate signing secret for verification.

01 · Create a fresh Make API key

In Make, create a Custom webhook with API-key authentication. Generate a fresh key (do not reuse the one sent by email), then copy the URL and key. Use hook.eu1.make.com, hook.eu2.make.com, hook.us1.make.com or hook.us2.make.com.

02 · Add the webhook in EazyAL

Open Casa Oakdene → Property settings → Integrations → Add webhook, choose Make, and paste the webhook URL and the new Make key.

03 · Save EazyAL’s signing secret

After saving, EazyAL shows the signing secret once. Copy it to a protected secret store; it is separate from the Make API key.

04 · Send a test event

Press Send test event and confirm the webhook.test event arrives in your Make scenario. Set the scenario to process requests sequentially.

1 / EVENT

A privacy-safe registration update

A privacy-safe registration update

EazyAL sends registration.updated when a guest registration changes. Delivery is at least once: deduplicate by event_id and apply only newer revisions for each checkin_session_id.

EazyAL sends registration.updated when a guest registration changes. Delivery is at least once: deduplicate by event_id and apply only newer revisions for each checkin_session_id.

Useful fields to map

event_id — stable event ID; retries reuse it.

data.checkin_session_id — stable identity for the guest registration.

data.external_booking_ref — Monday booking ID carried on the guest link.

data.status — current registration state (for example, ready_for_review); data.revision increases for each registration.

data.guests — expected, completed, SIBA-required and accepted counts.

data.blocker_codes and sendable_now — why a registration is waiting or ready.

{

"schema_version": 1,

"event_id": "11111111-1111-4111-8111-111111111111",

"type": "registration.updated",

"occurred_at": "2026-10-02T10:00:00Z",

"data": {

"checkin_session_id": "33333333-3333-4333-8333-333333333333",

"external_booking_ref": "CO-123323211",

"revision": 3,

"status": "ready_for_review",

"guests": { "expected": 2, "completed": 2 },

"sendable_now": false,

"blocker_codes": ["stay_unlinked"]

}

}

A registration.updated event contains IDs, status, counts and blockers, never guest names, contact details, nationalities or document details.

2 / AUTHENTICATION

Verify every event before using it

Verify every event before using it

Each webhook request carries a Standard Webhooks signature. Make requests also include x-make-apikey for the API-key authentication configured on the Custom webhook.

Each webhook request carries a Standard Webhooks signature. Make requests also include x-make-apikey for the API-key authentication configured on the Custom webhook.

Verify the signature

Standard Webhooks libraries can verify the raw signed content `<webhook-id>.<webhook-timestamp>.<raw body>` using the full `whsec_...` secret. For manual HMAC verification, remove the prefix and base64-decode the remainder.

Read webhook-id, webhook-timestamp and webhook-signature. Reject timestamps more than five minutes old.

Keep both keys private

The EazyAL signing secret appears once and is different from the Make API key. Keep both out of Monday columns and unprotected scenario history; use protected credential storage or a small server-side relay.

05 / GUEST LINK

Build each guest link on one line

Build each guest link on one line

Create one random session ID per Monday booking and save it on that item. Reuse it for every guest in the party; set guests to the party size and external_booking_ref to the Monday booking ID.

Create one random session ID per Monday booking and save it on that item. Reuse it for every guest in the party; set guests to the party size and external_booking_ref to the Monday booking ID.

One-line guest URL

https://app.eazyal.com/guestViewPageExternal?publicToken=<the property's link token>&session=<a random ID saved on the Monday item>&guests=<party size>&external_booking_ref=<Monday booking ID>

Use the property’s guest-link token as publicToken.

Save the generated session ID to the Monday item before sending the link.

Reuse one session ID for every guest on the booking. Keep all query parameters on this single URL line.

Match registration events to Monday

{

"data.external_booking_ref": "CO-123323211",

"data.checkin_session_id": "33333333-3333-4333-8333-333333333333",

"data.status": "ready_for_review",

}

Store checkin_session_id → Monday item ID and the last applied revision. Process requests sequentially; ignore duplicate or older revisions. Route missing or multiple booking matches to an error path.

PRIVACY AND WORKFLOW

Keep guest details inside EazyAL

Keep guest details inside EazyAL

Registration events contain IDs, status, counts and blockers—not guest names, contacts, nationalities or identity documents. Review the guest record inside EazyAL.

Registration events contain IDs, status, counts and blockers—not guest names, contacts, nationalities or identity documents. Review the guest record inside EazyAL.

Monday is not the guest record

Monday stores booking and registration IDs for matching. Guest identity and documents remain available only in EazyAL to users with property access.

EazyAL keeps the review gate

Make can keep Monday current, but an authorized host or operator reviews guest records and handles SIBA inside EazyAL.

Rotate credentials safely

Replace the EazyAL signing secret in webhook settings if it is exposed. To rotate Make’s API key, delete and recreate that webhook with the new key.

SCOPE AND DELIVERY

Registration webhook behavior

Registration webhook behavior

When events are sent

Events update as guests register, stays are linked, party sizes are confirmed, SIBA progresses, registrations are cancelled or an arrival becomes sendable. Payloads contain no guest PII.

Retries, duplicates and revisions

Delivery is at least once. Transient failures retry with backoff for up to 24 hours; duplicate deliveries keep the same event_id. Newer revisions supersede older undelivered updates. Save the last applied revision per checkin_session_id.

Use event_id to deduplicate, checkin_session_id as the registration key, and external_booking_ref to find the Monday item. Never match by guest name or stay dates.

We use cookies to improve your experience. By continuing, you agree to our cookie policy.