reservation.message.sent

A host-side message was sent on a reservation thread — in the channel's own app (e.g. the Airbnb app; source: "channel") or through Repull (source: "repull": the API, the dashboard, an automation or AI). Sent once per message, whichever copy Repull stores first. externalMessageId and messageId match GET /v1/conversations/{id}/messages. Currently Airbnb and Booking.com.

Payload

Every delivery uses the same outer envelope (event, eventId, apiVersion, timestamp, data). Dedupe on eventId — it stays stable across retries and replays, while the X-Repull-Delivery-Id header changes on every attempt.

{
  "event": "reservation.message.sent",
  "eventId": "3f1c9a2e-8b7d-4c6a-9e0f-1a2b3c4d5e6f",
  "apiVersion": "2026-04",
  "timestamp": "2026-05-01T12:34:56.000Z",
  "data": {
    "reservationId": "235970",
    "threadId": "900301",
    "from": {
      "type": "host",
      "name": "Casey"
    },
    "body": "The unit is free from the 18th, so an early check-in should work. I will confirm by noon.",
    "sentAt": "2026-09-25T13:02:17.000Z",
    "messageId": "1854462",
    "externalMessageId": "32877308873",
    "externalThreadId": "2648057088",
    "confirmationCode": "HMJTFCEDFB",
    "listingId": "23893",
    "channel": "airbnb",
    "source": "channel",
    "direction": "outbound",
    "senderType": "host",
    "senderName": "Casey",
    "senderAvatar": null,
    "translatedBody": null,
    "attachments": [],
    "isAutomated": false,
    "aiGenerated": false,
    "status": null,
    "revision": "2026-09-25T13:02:17.000Z"
  }
}

Verifying signatures

Every delivery includes a timestamped X-Repull-Signature header of the form t=<unix_ts>,v1=<hex>, where v1 is HMAC-SHA256(signing_secret, `${t}.${raw_body}`). Verify it before processing — see Verify Signatures for full Node.js and Python examples.

Use the raw body

Sign the raw request body exactly as received, not a re-stringified JSON object. Re-serialisation can reorder keys or change whitespace and break the signature.

Tip: Acknowledge with a 2xx status within 10 seconds. Failed deliveries are retried up to 5 times with exponential backoff.Webhook reliability →

AI