API & Webhooks

What the Salonnare API and webhooks are, what you use them for and how to create API keys and webhooks.

API & Webhooks

With the Salonnare API and webhooks you connect your salon to other software: your accounting package, your own website, a newsletter service or a custom dashboard. You do not need to be a developer to understand what they do -- this page explains it calmly.

Not available yet

This feature is still marked Soon in the app: you can't create API keys or webhooks at the moment. If you open Settings > API & Webhooks, you only see a notice that the feature is on its way. This page describes how it will work once the feature is available.

What is an API?

An API (Application Programming Interface) is an agreement that lets two programs talk to each other. Where you click a button in the app to load an appointment, another program can request the same data through the API -- automatically and without manual steps.

Practical examples for a salon:

  • Your accounting software automatically pulls your revenue every night.
  • Your own website shows your services and prices straight from Salonnare.
  • An integration partner syncs your client list.

Access to the API works through an API key: a secret code that proves the request comes from you. Treat that key like a password.

Creating an API key

  1. Go to Settings -> API & Webhooks.
  2. On the API keys tab, click New key.
  3. Give the key a recognisable name (for example "Accounting") and choose the permissions: Read only, Read + write or Full access. Right now, an API key can only ever fetch data, regardless of which permission level you choose; a read-only key can never do more than that anyway.
  4. Copy the key immediately and store it safely. For security reasons Salonnare shows the full key only once.

Suspect a key has leaked? Delete it right away -- every integration using that key stops immediately.

What is a webhook?

A webhook is the reverse of the API. Instead of you fetching data, Salonnare automatically sends a message to an address (URL) of yours the moment something happens. The other software no longer has to keep asking "is there anything new?" -- it gets a signal by itself.

Salonnare can send these six events:

  • booking.created -- an employee creates an appointment in the app
  • booking.updated -- an employee changes an appointment in the app (including a status change to completed or no-show)
  • booking.cancelled -- an employee cancels an appointment in the app
  • payment.received -- an employee completes a checkout in the POS
  • client.created -- an employee creates a client in the app
  • client.updated -- an employee changes client details in the app
Only what happens in the app

Every event comes from an employee's action in the app. An online booking through your booking page or Google, a client cancelling by herself, a waitlist conversion, a repeating series, a treatment plan and a client creating herself on the booking page do not (yet) send a notification. Mention this to your integration partner: they can catch the missed appointments by fetching the appointment list periodically.

Setting up a webhook

  1. Go to Settings -> API & Webhooks and open the Webhooks tab.
  2. Click New webhook.
  3. Enter the URL where Salonnare should send the notifications (your integration partner or developer provides this).
  4. Choose the events you want to react to.
  5. Save. You can then review the delivery logs to see whether the notifications arrive correctly.

The secret Salonnare uses to sign the messages is shown the moment you save the webhook -- store it safely right away, just like an API key, because Salonnare will not show it again. If you lose it, click the refresh icon next to the webhook (Request a new secret); you'll then see a new secret once. The old secret stops working from that moment on, so the receiving end needs updating too.

Every webhook notification carries a signature the receiver can use to verify the message really came from Salonnare.

Working securely

  • Never share API keys publicly (not in email, screenshots or code posted online).
  • Give an integration only the permissions it truly needs -- choose read-only where possible.
  • Delete keys and webhooks you no longer use.

Because Salonnare processes your data in the EU and you decide which integrations get access, you keep full control over your data. Need help with an integration? Feel free to reach out through the support page.

Are you a developer looking for the technical details (authentication, endpoints, fields, error codes, signature verification)? See the API Reference.

Related articles