Skip to main content

webhooks

Events YardSpot sends to your systems as they happen.

Registering an endpoint. A tenant administrator adds endpoints per event type in the YardSpot app. Each endpoint has a URL and an optional secret of at least 16 characters.

Delivery. YardSpot sends an HTTP POST with a JSON body to every endpoint subscribed to the event's type. Events of one type are delivered in order. Delivery is at most once: a request that fails or returns an error is not retried, so treat webhooks as a prompt to act and use the API as the source of truth if you need to reconcile. Respond quickly with any 2xx.

Body. Every event uses the same envelope: the event type, when it was published, and the event itself in data.

{
"type": "YARDSPOT_GATE_IN",
"time": "2026-10-05T14:03:22.418Z",
"data": { "assetId": "TRLU1234567", "gateId": "...", "visitId": "...", "timestamp": 1759673002418 }
}

Verifying a request. When the endpoint has a secret, YardSpot sends X-Signature: sha256=<hex>, the HMAC-SHA256 of the raw request body keyed with your secret. Compute the same HMAC over the body bytes you received, before parsing them, and compare in constant time.