review.created

A new review was received on a reservation — from the guest (about the host/property) or the host (about the guest). reviewerRole disambiguates. Detected on the next review sync; providers do not push reviews in real time, so latency is bounded by the sync interval.

Payload

Every delivery uses the same outer envelope (event, eventId, apiVersion, timestamp, data). Dedupe on eventId — it stays stable across retries and replays, while the X-Repull-Delivery-Id header changes on every attempt.

{
  "event": "review.created",
  "eventId": "3f1c9a2e-8b7d-4c6a-9e0f-1a2b3c4d5e6f",
  "apiVersion": "2026-04",
  "timestamp": "2026-05-01T12:34:56.000Z",
  "data": {
    "object": {
      "id": "90210",
      "channel": "airbnb",
      "listingId": "5668",
      "reservationId": "215906",
      "customerId": "1",
      "reviewerRole": "guest",
      "rating": 5,
      "submittedAt": "2026-05-01T09:00:00.000Z",
      "externalReviewId": "1548751920482971044",
      "airbnbListingId": "2628",
      "confirmationCode": "HMEXAMPLE1",
      "publicReview": "Spotless flat, five minutes from the station. Taylor was quick to answer.",
      "privateFeedback": "The second bedroom radiator was cold on the first night.",
      "recommended": true,
      "overallRating": 5,
      "response": null,
      "responded": false,
      "respondByAt": "2026-05-15T09:00:00.000Z",
      "hidden": false,
      "createdAt": "2026-05-01T09:00:00.000Z",
      "updatedAt": "2026-05-01T09:00:00.000Z"
    },
    "revision": "2026-05-01T09:00:00.000Z"
  }
}

Verifying signatures

Every delivery includes a timestamped X-Repull-Signature header of the form t=<unix_ts>,v1=<hex>, where v1 is HMAC-SHA256(signing_secret, `${t}.${raw_body}`). Verify it before processing — see Verify Signatures for full Node.js and Python examples.

Use the raw body

Sign the raw request body exactly as received, not a re-stringified JSON object. Re-serialisation can reorder keys or change whitespace and break the signature.

Tip: Acknowledge with a 2xx status within 10 seconds. Failed deliveries are retried up to 5 times with exponential backoff.Webhook reliability →

AI