Rex

Get started with the Rex API and webhooks

The Rex API lets your own systems read and change your account's data: reservations, venues, packages, customers and more. Webhooks work the other way round: Rex posts an event to your system the moment something happens, such as a new booking. Both are set up on the API page.

โ„น๏ธNote

The API page is part of the Rex Growth and Rex Enterprise plans. On other plans it shows Upgrade Your Plan instead.

Create an API key

Give each system its own key, named after where it is used. You can then rotate or delete one system's access without breaking the others.

1

Navigate to the API page

The API Keys tab lists every key you have, each in its own card.

Settingsโ€บAPI
The API page under Settings, with the API item in the sidebar and the Add Key card's Key Name field and Add Key button highlighted
Settings > API. Client IDs are masked in this screenshot.
2

Enter a key name and generate the key

Type a name in Key Name, for example Production, then click Generate. Once you have a key, the card is called Add Key and the button reads Add Key.

The API Keys tab with the Key Name field filled in with Production and the Generate button marked (2)
Type a name in Key Name, then click Generate.
3

Copy the Client ID and Client Secret

The new key's card shows both values with a copy button and the message "Make sure to copy your Client Secret now. You won't be able to see it again." Copy both into your system, then click Done. After that the secret shows as dots and cannot be shown again.

A new API key's card with its Client ID and Client Secret, their copy buttons, the copy-now warning and the Done button (3); demo placeholder values
Copy the Client ID and Client Secret now, then click Done.

Get an access token

Your system does not send the key itself on each call. It exchanges the Client ID and Client Secret for an access token, then sends the token with every request:

http
POST https://app.reservewithrex.com/api/api-key/token
Content-Type: application/json

{ "clientId": "<Client ID>", "clientSecret": "<Client Secret>" }

-> { "token": "<access token>" }

Authorization: Bearer <access token>

A token is valid for one hour. When it expires, your system requests a new one the same way. Keep the Client Secret on your server, never in a web page or app that guests can open.

โš ๏ธWarning

A token acts as an admin of your whole account, for every venue. Treat the Client Secret like a password, and never paste it into a shared document, a ticket or a chat message.

Find the endpoints

Click View API Docs at the top of the API page. It appears once you have at least one key, and opens the full endpoint reference in a new tab, grouped by area, with a sample request for each endpoint. The docs stay open for about two hours; after that, click View API Docs again.

Rotate or delete a key

Rotate Key issues a new Client Secret for that key and shows it once, just like a new key. The Client ID stays the same, and the old secret stops working straight away, so update your system at the same time. Use it when a secret may have leaked, or when someone who knew it leaves.

Delete Key removes the key after a confirmation. Any system using it loses access. In both cases, a token your system already received keeps working until it expires, at most one hour later.

Send events with webhooks

A webhook endpoint is an address on your own system that Rex posts events to, for the venues you choose.

1

Click the Webhooks tab

It sits next to API Keys on the same page.

Settingsโ€บAPIโ€บWebhooks
The Webhooks tab marked (1) next to API Keys on the API page, with the Add Endpoint card below
The Webhooks tab sits next to API Keys.
2

Enter the endpoint details

In Add Endpoint, enter a Name, pick one or more Venues, and enter the Endpoint URL. Then click Add Endpoint. A new endpoint is sent every event type.

The Webhooks tab of the API page, with the Add Endpoint card's Name, Venues and Endpoint URL fields and an existing endpoint's Send Test button highlighted
The Webhooks tab: add an endpoint, then send a test.
3

Copy the signing secret

The new endpoint's card shows its Signing Secret once, with the message "Copy your signing secret now. You won't be able to see it again." Copy it into your system, then click Done.

A new webhook endpoint's card showing its signing secret with the copy-now warning and the Done button (3); demo placeholder values
Copy the signing secret now, then click Done.
4

Choose the events to send

Under Events to send, turn off any event your system does not need. The switch next to Active / Paused turns the whole endpoint on or off.

A webhook endpoint card with the Active / Paused switch and Events to send list (4) and the Send Test button (5)
Turn off the events your system doesn't need, then send a test.
5

Send a test

With the endpoint Active, click Send Test. Rex posts a sample reservation.created event whose data says "test": true, so you can check that your system receives it.

A webhook endpoint card with the Active switch and the Send Test button marked (5)
With the endpoint Active, click Send Test.

These are the events an endpoint can receive. The Event Reference card at the bottom of the Webhooks tab shows the exact body Rex posts for each one.

FieldDescription
reservation.createdA reservation is created.
reservation.updatedA reservation is updated. The changed_fields object lists what changed.
reservation.cancelledA reservation is cancelled or deleted.
reservation.checkinThe check-in status of a reservation changes.
reservation.paymentA payment is recorded against a reservation. Covers card payments and refunds through Heartland, Stripe, Square, Teya and GoTab.
reservation.resources_changedThe resources assigned to a reservation change. A bulk change sends one event per venue, listing that venue's reservations.
block.createdA block is created.
block.updatedA block is updated.
block.removedA block is removed.
waitlist.joinedA guest joins the waitlist.

Check that a webhook came from Rex

Every request carries three headers:

  • X-Rex-Signature: t=<timestamp>,v1=<signature>. The signature is an HMAC-SHA256, in hex, of <timestamp>.<raw request body>, keyed with the endpoint's signing secret.
  • X-Rex-Event-Id: a unique id for the event, so your system can ignore a repeat.
  • X-Rex-Event-Type: the event, for example reservation.created.

Rotate Secret issues a new signing secret. For the next 24 hours each request carries a second v1 signature made with the old secret, so you can switch over without missing events.

Your endpoint should answer with a 2xx status within 5 seconds. If it does not, Rex tries again after 1, 5 and 15 minutes, then after 1, 3, 6, 12 and 24 hours, and then gives up on that event.

Updated Oct 8, 2026

Was this helpful?