reservation.alteration.created

A new reservation alteration (change of dates, guest count, or price) was requested — currently Airbnb only. Detected on the next alteration sync after the request lands upstream.

Payload

Every delivery uses the same outer envelope (event, eventId, apiVersion, timestamp, data). Dedupe on eventId — it stays stable across retries and replays, while the X-Repull-Delivery-Id header changes on every attempt.

{
  "event": "reservation.alteration.created",
  "eventId": "3f1c9a2e-8b7d-4c6a-9e0f-1a2b3c4d5e6f",
  "apiVersion": "2026-04",
  "timestamp": "2026-05-01T12:34:56.000Z",
  "data": {
    "object": {
      "id": "4471",
      "alterationId": "RAX9K2M4C1",
      "channel": "airbnb",
      "reservationId": "215906",
      "customerId": "1",
      "status": "pending",
      "initiator": "guest",
      "confirmationCode": "HMEXAMPLE1",
      "platform": "airbnb",
      "reason": null,
      "notes": "Flight moved, can we stay two more nights?",
      "currency": "GBP",
      "original": {
        "checkIn": "2026-06-10",
        "checkOut": "2026-06-16",
        "guestCount": 2,
        "totalPrice": "1320.00",
        "listingId": "5668"
      },
      "requested": {
        "checkIn": "2026-06-10",
        "checkOut": "2026-06-18",
        "guestCount": 2,
        "totalPrice": "1760.00",
        "listingId": "5668",
        "airbnbListingId": null
      },
      "createdAt": "2026-05-01T13:00:00.000Z",
      "updatedAt": "2026-05-01T13:00:00.000Z",
      "respondedAt": null
    },
    "changes": {
      "checkOut": {
        "from": "2026-06-16",
        "to": "2026-06-18"
      },
      "totalPrice": {
        "from": "1320.00",
        "to": "1760.00"
      }
    },
    "revision": "2026-05-01T13:00:00.000Z"
  }
}

Verifying signatures

Every delivery includes a timestamped X-Repull-Signature header of the form t=<unix_ts>,v1=<hex>, where v1 is HMAC-SHA256(signing_secret, `${t}.${raw_body}`). Verify it before processing — see Verify Signatures for full Node.js and Python examples.

Use the raw body

Sign the raw request body exactly as received, not a re-stringified JSON object. Re-serialisation can reorder keys or change whitespace and break the signature.

Tip: Acknowledge with a 2xx status within 10 seconds. Failed deliveries are retried up to 5 times with exponential backoff.Webhook reliability →

AI