listing.created
A new property was synced into Repull from a connected PMS or channel.
Payload
Every delivery uses the same outer envelope (event, eventId, apiVersion, timestamp, data). Dedupe on eventId — it stays stable across retries and replays, while the X-Repull-Delivery-Id header changes on every attempt.
{
"event": "listing.created",
"eventId": "3f1c9a2e-8b7d-4c6a-9e0f-1a2b3c4d5e6f",
"apiVersion": "2026-04",
"timestamp": "2026-05-01T12:34:56.000Z",
"data": {
"object": {
"id": "6250",
"customerId": "1",
"channel": "airbnb",
"externalListingId": "1234567890123456789",
"name": "Lakeview Loft — Example City",
"active": true,
"listed": true,
"channels": [
{
"platform": "airbnb",
"externalId": "1234567890123456789",
"active": true,
"syncEnabled": true,
"syncCategory": "sync_all"
}
],
"address": {
"city": "Radium Hot Springs",
"region": "BC",
"country": "CA"
},
"bedrooms": 2,
"bathrooms": 2,
"maxGuests": 6,
"thumbnailUrl": "https://a0.muscache.com/im/pictures/…",
"createdAt": "2026-05-01T12:00:00.000Z",
"updatedAt": "2026-05-01T12:00:00.000Z"
},
"revision": "2026-05-01T12:00:00.000Z"
}
}Verifying signatures
Every delivery includes a timestamped X-Repull-Signature header of the form t=<unix_ts>,v1=<hex>, where v1 is HMAC-SHA256(signing_secret, `${t}.${raw_body}`). Verify it before processing — see Verify Signatures for full Node.js and Python examples.
Use the raw body
Sign the raw request body exactly as received, not a re-stringified JSON object. Re-serialisation can reorder keys or change whitespace and break the signature.
Tip: Acknowledge with a 2xx status within 10 seconds. Failed deliveries are retried up to 5 times with exponential backoff.Webhook reliability →
AI