# Webhooks

Webhook configuration and event notifications.
Altegio sends HTTP POST notifications to your configured URLs when
events occur in subscribed locations. Each notification contains a JSON payload
with the event envelope (`company_id`, `resource`, `resource_id`, `status`)
and resource-specific `data` (an empty array for schedule changes).
**Delivery details:**
- Method: POST
- Content-Type: application/json
- Queue delay: 5 seconds after the event
- Each attempt has a 10-second total timeout and a 5-second connection timeout
- Requests carry the shared configured `Authorization: Bearer` token, not a
secret unique to your webhook URL
- Requests carry an `X-Hook-Id` header: a UUID that identifies the event
notification and stays the same across its retries
- Your endpoint must respond with a 2xx status code

**Configuration:** Use the [Webhook Settings](#tag/Webhooks/operation/get_event_notification_settings)
endpoint to subscribe to specific resource types.
**Retry behavior:**
- Delivery is at-least-once: deduplicate notifications by `X-Hook-Id`
- Failures before the request reaches your endpoint (connection refused, DNS
or TLS failure, connection timeout), HTTP 429, and HTTP 5xx are retried up
to twice: 5 seconds and then 30 seconds after the previous attempt
- A retry carries the current state of the resource, so its `data` can differ
from the first attempt
- A timeout after the request was sent and other HTTP 4xx responses are not retried
- Notifications for different events are not guaranteed to arrive in order
- The final result is recorded internally; there is no partner-facing
delivery log, test-send, or replay endpoint

**Location events:** Location settings changes use `resource: company` in
the payload; existing `salon` events remain accepted by the delivery
system. The canonical `/locations` API URL alias does not rename webhook
payload resources.

 - [GET /hooks_settings/{location_id}](https://developer.alteg.io/en/developers/openapi/webhooks/get_event_notification_settings.md): Read location-wide webhook settings. Requires webhook settings read access. `url_settings` contains the actual flags for each destination; the legacy top-level flags reflect only the first URL. This p
 - [POST /hooks_settings/{location_id}](https://developer.alteg.io/en/developers/openapi/webhooks/update_event_notification_settings.md): Replace the complete location-wide URL set and apply one event-flag set to every supplied destination. Omitted flags default to 0. Requires webhook settings read access and permission to edit the loca
 - [POST SalonEvent](https://developer.alteg.io/en/developers/openapi/webhooks/webhook_salon.md): Location settings changes are sent with `resource: company`. Legacy `salon` events remain compatible. The `/locations` API URL alias does not change the webhook resource name. `delete` is sent once, w
 - [POST StaffEvent](https://developer.alteg.io/en/developers/openapi/webhooks/webhook_staff.md): Sent when a team member is created, updated, or deleted. The `data` field matches the response from `GET /company/{company_id}/staff/{staff_id}`.
 - [POST ServiceEvent](https://developer.alteg.io/en/developers/openapi/webhooks/webhook_service.md): Sent when a service is created, updated, or deleted. The `data` field matches the response from `GET /company/{company_id}/services/{service_id}`.
 - [POST ServiceCategoryEvent](https://developer.alteg.io/en/developers/openapi/webhooks/webhook_service_category.md): Sent when a service category is created, updated, or deleted. The `data` field matches the response from `GET /company/{company_id}/service/categories`.
 - [POST ClientEvent](https://developer.alteg.io/en/developers/openapi/webhooks/webhook_client.md): Sent when a client is created, updated, or deleted. The `data` field contains the full client profile with all default includes.
 - [POST RecordEvent](https://developer.alteg.io/en/developers/openapi/webhooks/webhook_record.md): Sent when an appointment is created, updated, or deleted. The `data` field matches the response from `GET /record/{company_id}/{record_id}`.
 - [POST LoyaltyCardEvent](https://developer.alteg.io/en/developers/openapi/webhooks/webhook_loyalty_card.md): Sent when a loyalty card is created, updated, or deleted. Uses a simplified payload with essential fields only.
 - [POST ScheduleEvent](https://developer.alteg.io/en/developers/openapi/webhooks/webhook_schedule.md): Sent when a team member's schedule changes, including when the team member loses timetable access and their future schedules are removed. Only `update` is emitted. The existing `staff` update notifica
 - [POST GoodEvent](https://developer.alteg.io/en/developers/openapi/webhooks/webhook_good.md): Sent when a product is created, updated, or deleted. The `data` field matches the response from `GET /goods/{company_id}/{good_id}`.
 - [POST GoodsOperationEvent](https://developer.alteg.io/en/developers/openapi/webhooks/webhook_goods_operation.md): Sent when a product operation occurs: sale, receipt, consumable write-off, product write-off, or product movement. The `resource` field indicates the specific operation type: `goods_operations_sale`,
 - [POST FinancesOperationEvent](https://developer.alteg.io/en/developers/openapi/webhooks/webhook_finances_operation.md): Sent when a financial transaction is created, updated, or deleted. May optionally include `payment_system_transaction_ids` if the feature is enabled for the location.
