Webhooks
Outbound. Configure them under Settings → Webhooks (owner or manager with manage_settings), not through this API.
- Events:
machine.created,machine.status_changed,issue.created,issue.resolved,maintenance.completed,work_order.completed - Per endpoint: event selection, on/off, HMAC secret (can be rotated), ping test
- Headers on each delivery:
X-GymMaintain-Event,X-GymMaintain-Delivery(idempotency key),X-GymMaintain-Signature(HMAC-SHA256of the raw body with the endpoint secret) - Retries: 5 attempts with backoff (1m → 1h), then
failedplus a manual retry - Delivery log with HTTP status and attempts
Verify the signature (example):
import hmac
sig = hmac.new(secret.encode(), request.body, 'sha256').hexdigest()
assert hmac.compare_digest(sig, request.headers['X-GymMaintain-Signature'])