reservation.message.received
A new inbound message arrived on a reservation thread.
Payload
Every delivery uses the same outer envelope (event, eventId, apiVersion, timestamp, data). Dedupe on eventId — it stays stable across retries and replays, while the X-Repull-Delivery-Id header changes on every attempt.
{
"event": "reservation.message.received",
"eventId": "3f1c9a2e-8b7d-4c6a-9e0f-1a2b3c4d5e6f",
"apiVersion": "2026-04",
"timestamp": "2026-05-01T12:34:56.000Z",
"data": {
"reservationId": "215906",
"threadId": "thr_01HX5XPQ2K",
"from": {
"type": "guest",
"name": "Alex Morgan"
},
"body": "Hi! What time can we check in?",
"sentAt": "2026-05-01T15:00:00.000Z",
"messageId": "1847801",
"externalMessageId": "32837172376",
"externalThreadId": "2603530383",
"confirmationCode": "HMEXAMPLE1",
"listingId": "5668",
"channel": "airbnb",
"direction": "inbound",
"senderType": "guest",
"senderName": "Alex Morgan",
"senderAvatar": null,
"translatedBody": null,
"attachments": [
{
"id": "88412",
"url": "https://files.example.com/message-attachments/1847801-1714575600000-k3j9x2m1q.jpg",
"imageUrl": "https://files.example.com/message-attachments/1847801-1714575600000-k3j9x2m1q.jpg",
"type": "image",
"contentType": "image/jpeg",
"createdAt": "2026-05-01T15:00:02.000Z"
}
],
"isAutomated": false,
"aiGenerated": false,
"status": "received",
"revision": "2026-05-01T15:00:00.000Z"
}
}Verifying signatures
Every delivery includes a timestamped X-Repull-Signature header of the form t=<unix_ts>,v1=<hex>, where v1 is HMAC-SHA256(signing_secret, `${t}.${raw_body}`). Verify it before processing — see Verify Signatures for full Node.js and Python examples.
Use the raw body
Sign the raw request body exactly as received, not a re-stringified JSON object. Re-serialisation can reorder keys or change whitespace and break the signature.
Tip: Acknowledge with a 2xx status within 10 seconds. Failed deliveries are retried up to 5 times with exponential backoff.Webhook reliability →
AI