Skip to content
Widgets & Embeds

Build on top of your booking platform

Enterprise website API keys expose approved booking, game, and availability data for custom websites. Webhooks fire on booking events with HMAC-SHA256 signing for secure delivery.

01

Website API access for approved accounts

Enterprise and approved custom accounts can generate website API keys for external sites and automation workflows. Keys are tenant-scoped, revocable, and separate from staff dashboard logins.

  • -Website API keys for external venue websites
  • -Tenant-scoped access to approved booking and game data
  • -Revocable hashed keys with last-seen tracking
  • -Separate machine-to-machine authentication
02

Real-time webhook notifications

Webhook notifications fire on every booking event — new bookings, cancellations, check-ins, and payment events. Delivered to your endpoint with HMAC-SHA256 signing for secure, verifiable delivery. No polling required.

  • -Webhooks for booking creation, cancellation, and completion
  • -Payment event notifications
  • -HMAC-SHA256 signed payloads for security
  • -Automatic retry with exponential backoff
03

Custom integrations and automation

Use Enterprise or approved custom access to connect Riddlio with external websites and automation workflows. Sync approved booking events to CRM, marketing, inventory, accounting, or reporting tools through tenant-scoped website API keys and signed webhooks.

  • -Approved CRM and marketing automation workflows
  • -Signed booking and payment event notifications
  • -Custom reporting for Enterprise accounts
  • -Tenant-scoped website API keys with revocation

FAQ

Common questions about REST API & Webhooks

Is API access included on all plans?+
Website API keys are available on Enterprise or approved custom accounts. Standard dashboard APIs power the Riddlio app for all plans, but external website API key access is separately enabled.
How are webhooks secured?+
Every webhook payload is signed with HMAC-SHA256 using your secret key. You verify the signature on your endpoint to ensure the payload came from Riddlio. We also include a timestamp to prevent replay attacks.
What happens if my webhook endpoint is down?+
Riddlio retries failed webhook deliveries with exponential backoff for up to 24 hours. You can view delivery attempts and manually retry from your dashboard. Failed webhooks are also logged for debugging.

Ready to see it in your venue?

Start your 14-day free trial and configure Riddlio around your rooms, sessions, payments, waivers, and team.