Read and change bookings, clients and the salon's catalogue from your own systems. API keys are made by the salon under Integrations; apps connect through a consent screen.
In the admin: Integrations → API & webhooks → create a key with the access you need.
Send it with every request as the X-API-Key header.
Every answer is {"success", "data", "error", "code", "meta"}; lists page with meta.next_cursor.
Webhooks
Signed POSTs when bookings, clients, payments, reviews or gift cards change. Verify X-BKG-Signature-V2 (HMAC-SHA256 of "timestamp.body").
Apps
Partner apps use OAuth 2 with PKCE: /oauth/authorize → /api/v1/oauth/token. Tokens are short-lived and the salon can revoke them.
v1
Versioning: v1 only grows — fields and endpoints are added, never removed or changed. Anything that breaks gets a new version and at least 12 months' notice.
X-BKG-Signature-V2
import hashlib, hmac
from datetime import datetime, timezone
def verify(raw_body: bytes, headers, secret: str, max_age_s: int = 300) -> bool:
ts = headers["X-BKG-Timestamp"]
if abs((datetime.now(timezone.utc) - datetime.fromisoformat(ts)).total_seconds()) > max_age_s:
return False
expected = hmac.new(secret.encode(), f"{ts}.".encode() + raw_body, hashlib.sha256).hexdigest()
sent = [headers.get("X-BKG-Signature-V2"), headers.get("X-BKG-Signature-V2-Previous")]
return any(s and hmac.compare_digest(expected, s) for s in sent)