sync.complete

Fired when a PMS/OTA data sync completes successfully.

Payload

Every delivery uses the same outer envelope (event, eventId, apiVersion, timestamp, data). Dedupe on eventId — it stays stable across retries and replays, while the X-Repull-Delivery-Id header changes on every attempt.

{
  "event": "sync.complete",
  "timestamp": "2026-04-04T03:00:00Z",
  "data": {
    "provider": "hostaway",
    "syncType": "full",
    "stats": { "listings": 15, "reservations": 42, "messages": 120 }
  }
}

Verifying signatures

Every delivery includes a timestamped X-Repull-Signature header of the form t=<unix_ts>,v1=<hex>, where v1 is HMAC-SHA256(signing_secret, `${t}.${raw_body}`). Verify it before processing — see Verify Signatures for full Node.js and Python examples.

Use the raw body

Sign the raw request body exactly as received, not a re-stringified JSON object. Re-serialisation can reorder keys or change whitespace and break the signature.

Example handler

if (event === 'sync.complete') {
  console.log('Sync done:', data.provider, data.stats)
}

Tip: Acknowledge with a 2xx status within 10 seconds. Failed deliveries are retried up to 5 times with exponential backoff.Webhook reliability →

AI