Skip to content
API & Webhooks

Connect Keruja to anything

Manage API keys, receive HMAC-signed webhooks for 15 event types, and bulk import/export via CSV. Public REST API and OpenAPI documentation coming soon.

Included in every plan. No add-on fees.

How It Works

Integrate in three steps

01

Generate an API key

Create org-scoped API keys from your dashboard settings. Each key carries scoped permissions and can be rotated without downtime. Keys are stored SHA-256 hashed, shown once at creation.

02

Configure webhooks

Subscribe to events and receive HMAC-SHA256-signed payloads at your endpoint. Verify signatures to ensure authenticity. Automatic retries with exponential backoff on failure.

03

Import and export data

Bulk import staff, events, clients, jobs, roles, and pay rates via CSV or XLSX. Export payroll runs, attendance records, and compliance reports. Full pipeline with validation and error reporting.

Capabilities

Everything you need to integrate

API key management

Create, rotate, and revoke org-scoped API keys with 12 permission scopes. SHA-256 hashed storage, rate limiting (600 req/min), and last-used tracking.

HMAC-SHA256 webhook signing

Every webhook payload is signed with your secret. Verify signatures server-side to guarantee authenticity and prevent tampering.

Webhook events (15)

shift.created, shift.offered, shift.accepted, shift.declined, shift.updated, shift.cancelled, shift.completed, report.generated, attendance.submitted, attendance.verified, notification.sent, staff.created, staff.updated, event.created, event.updated.

Sandbox/test mode

Test environment with isolated data. API keys use evk_test_* prefix to distinguish sandbox from production.

Coming soon

Public REST API

Full CRUD endpoints for shifts, staff, jobs, events, and payroll, accessible via API key authentication. Currently in development.

Coming soon

OpenAPI documentation

Interactive Swagger UI with request/response examples, authentication guides, and a try-it-out sandbox. Currently in development.

600 requests per minute per key · HMAC-SHA256 signatures with replay protection · Every call logged with timestamp, endpoint and status.

See how your next event would run in Keruja.

A personalised walkthrough focused on how you currently recruit, staff and review worked time. Bring a real event and we will build it in Keruja on the call, with your jobs, your shifts and your rates.

API & Webhooks: Build Custom Integrations | Keruja