# Webhook from Altegio About Application Events

This is an example receiver path on your application backend, not an Altegio
API endpoint. Altegio POSTs to the application's configured `callback_url`.
It is separate from location entity `webhook_urls`.
This section describes how Altegio sends webhook notifications when specific events occur in the application-to-location lifecycle. The following event types are currently supported:
* uninstall — Sent when the application is disabled on the Altegio side.
* freeze — Sent when the integration is frozen due to service expiration.
* payment — Sent after an Altegio Marketplace billing payment is processed.

Lifecycle callbacks are emitted only in the production environment. The
`partner_token` field lets the receiving application verify which partner
originated the callback. Compare it with the expected token using a
constant-time comparison. A payment event also includes the payment fields
documented below and a HMAC signature. Other lifecycle events do not carry
that signature.
Configure `callback_url` in your Altegio Developer Account. There is no
partner-facing delivery log, test-send, or replay API for these callbacks.

Endpoint: POST /marketplace_webhook
Version: 1.0.0

## Request fields (application/json):

  - `salon_id` (number, required)
    Location ID.
    Example: 123

  - `application_id` (number, required)
    Application ID.
    Example: 123

  - `event` (string, required)
    Event Slug.
    Enum: "uninstall", "freeze", "payment"

  - `partner_token` (string, required)
    Partner token included in the JSON body to verify the callback origin.
    Example: yasdfkjah2328aj

  - `payment_id` (integer)
    Marketplace payment ID. Present for `payment`.

  - `amount` (number)
    Payment amount. Present for `payment`.

  - `currency_iso` (string)
    ISO currency code. Present for `payment`.

  - `discount` (number | null)
    Applied discount. Present for `payment`.

  - `period_from` (string)
    Paid period start. Present for `payment`.

  - `period_to` (string)
    Paid period end. Present for `payment`.

  - `payment_date` (string)
    Payment timestamp. Present for `payment`.

  - `tariff_option_id` (integer | null)
    Marketplace tariff option. Present for `payment`.

  - `sign` (string)
    HMAC-SHA256 over the URL-encoded `salon_id`, `amount`, and `discount` fields, in that order, using the partner token.

## Response 200:

  - `200` (unknown)
    From the side of the partner, a response code of successful processing (200-299) is expected.

## Response 401:

  - `401` (unknown)
    Unauthorized

## Response 401 fields (application/json):

  - `success` (boolean)
    Response status.
    Example: false

  - `data` (object | null)
    Response data.
    Example: null

  - `meta` (object)
    Additional response data.

  - `meta.message` (string)
    Error message.
    Example: Authentication needed.

## Response 403:

  - `403` (unknown)
    Forbidden

## Response 403 fields (application/json):

  - `success` (boolean)
    Response status.
    Example: false

  - `data` (object | null)
    Response data.
    Example: null

  - `meta` (object)
    Additional response data.

  - `meta.message` (string)
    Error message.
    Example: Access denied.

## Response 404:

  - `404` (unknown)
    Not Found

## Response 404 fields (application/json):

  - `success` (boolean)
    Response status.
    Example: false

  - `data` (object | null)
    Response data.
    Example: null

  - `meta` (object | array)
    Additional response data (empty object or empty array)
    Example: {}

