Skip to main content
Webhooks push booking lifecycle events to your server so you don’t have to poll. Register an HTTPS endpoint and Jinko sends a signed POST the moment a booking is confirmed or fails. The one-line version:

Prerequisites

  • A Jinko account and an API key (jnk_...). Get one.
  • An HTTPS endpoint that can receive a POST (must be https:// and publicly reachable).

1) Register an endpoint

Go to Dashboard → Webhooks, click Add webhook, paste your URL, pick the events, and Create. Copy the signing secret shown once. You’ll need it to verify deliveries.

2) Events

More event types will be added over time. Treat the event field as an open enum and ignore events you don’t handle.

3) Payload

Deliveries are intentionally thin: identifiers only, no traveler PII. Fetch full detail with get_booking using the booking_ref.
Each request also carries these headers:

4) Verify the signature

Compute HMAC-SHA256(secret, "<X-Jinko-Timestamp>.<raw request body>") and compare it, in constant time, to the hex in X-Jinko-Signature (after the sha256= prefix). Use the raw request body: parsing and re-serializing the JSON will change the bytes and break the check.
Reject the request if the signature doesn’t match, or if X-Jinko-Timestamp is older than your tolerance (e.g. 5 minutes) to guard against replays. Respond 2xx once you’ve accepted the event.

5) Retries & idempotency

  • A non-2xx response (or a timeout) is retried with exponential backoff, up to 8 attempts over several hours.
  • Retries mean you may receive the same event more than once. Deduplicate on X-Jinko-Event-Id (a given business event always carries the same id).
  • Return 2xx as soon as you’ve durably recorded the event; do slow work asynchronously so you don’t trip the delivery timeout.

6) Test it

Use Send test in the dashboard, or:
This delivers a sample event with "livemode": false and booking_ref: "JNK-TEST00", so you can confirm your signature handling end-to-end without a real booking.