Daykite
Developers

Build on your calendar, not around it.

Every meaningful change — an event created, a task completed, a booking made — is available as a signed webhook and a versioned REST API. Calendar manages time; what you build manages what happens because of it.

Authentication
API keys

Create one from Settings → Developer. Send it as Authorization: Bearer <key>. Scoped at creation — a key can only do what it was granted.

OAuth 2.0

Register an application, send a user through /oauth/authorize, exchange the code at /oauth/token. Standard authorization_code and refresh_token grants.

Managing keys, webhooks and apps themselves always requires a signed-in session — never a bearer token, so a leaked key can’t mint more access for itself.

Scopes
events:readevents:createevents:updateevents:deletecalendars:readcalendars:writeavailability:readtasks:readtasks:writeprojects:readprojects:writespaces:readroutines:readroutines:writebookings:readbookings:writenotifications:readnotifications:writeorganizations:readdevices:writesync:read

Grant only what an integration needs. A key with events:read alone can never create, change or delete anything.

The same API our apps use

No private back door.

The Daykite apps read and write through these same endpoints, with the same scopes. Three of them exist because a phone needs them, and they’re yours too.

GET /me/bootstrapYou, your Spaces, your calendars and a sync cursor — everything a first screen needs, in one request.
GET /sync?since=Everything that changed since a timestamp. Removed things come back two ways: rows carrying deletedAt, and a deleted list for what was truly erased.
POST /devicesRegister a push token. Sending the same one again updates that device instead of adding another, so reinstalling never doubles up.
Event catalog

What a webhook can subscribe to.

Subscribe to specific types, or ["*"] for everything. Every delivery is HMAC-SHA256 signed and retried on failure.

event.createdA new event was created.
event.updatedAn event's details or time changed.
event.cancelledAn event (or an occurrence of one) was cancelled.
task.createdA new task was created.
task.updatedA task's details changed.
task.completedA task was marked done.
task.assignedSomeone was assigned to a task. Sent to the person assigned.
task.due_changedA task's due date was set or moved.
task.deletedA task was deleted.
booking.createdSomeone booked time through a public booking page.
booking.cancelledA booking was cancelled, by the guest or the host.
booking.rescheduledA booking moved to a new time, by the guest or the host. Carries the previous start.
routine.createdA new routine was created.
routine.updatedA routine's name, days or periods changed.
routine.deletedA routine was deleted.
routine.period.completedA routine period was marked done for a day.
routine.period.skippedA routine period was skipped for a day.
whatsapp.receivedSomeone sent a message to a connected WhatsApp Business number. Carries who sent it and the text.
stripe.eventA payment, subscription or invoice event on a connected Stripe account. Carries the amount and customer.
form.submittedSomeone filled in a watched Typeform, Jotform or Google Form. Carries every answer.

Routine events cover changes to a routine and periods marked done or skipped. Time-based triggers (an event or routine period starting soon, ending) aren’t available yet.

Webhook security

Verify every delivery.

Each request carries X-Calendar-Signature, an HMAC-SHA256 of {timestamp}.{body} using your webhook’s secret — plus X-Calendar-Event, X-Calendar-Delivery and X-Calendar-Timestamp. Recompute the signature and compare before trusting a payload.

Full endpoint reference: /openapi.json. Manage everything from Settings → Developer.