# Webhooks `VERIFIED BOTH` ## Purpose Log inbound Nuitee events. Tokens never displayed on this page (live note). ## Who / permission `alya_hs_view_webhooks`. Staff: no. Agency Admin: yes. HMAC toggle: administrator settings. ## Where `#webhooks` · WP `page=alya-hs-webhooks` ## Screenshot ![Webhooks](../screenshots/backoffice/08-webhooks-01-overview.png) ## Fields observed “Événements inbound journalisés. HMAC inbound OFF.” KPI: **4** events, HMAC **OFF**. Endpoint: `https://alyatrip.com/wp-json/alya/v1/webhooks/nuitee`. Last event `2026-08-26 19:01:05`. Toggle HMAC inbound **OFF**. Table (anonymized): events `booking.book`, `booking.prebook`, `flight.prebook`; HTTP 200; HMAC `missing`; ENV Sandbox. ## Actions View. HMAC was **not** switched on (would change security posture). ## Backend / API `WebhookHandler` `POST /alya/v1/webhooks/nuitee`. Flight + Stripe webhook controllers also registered. HMAC default **off** in `WebhookAuth`. ## Database `alya_hs_webhook_events`. ## Security HMAC off means token-only inbound auth. `CONFIGURATION REQUIRED` to enable HMAC if Connect signs. ## 14. Evidence status `VERIFIED BOTH` ## Related [security-audit.md](../technical/security-audit.md) · [nuitee-liteapi-audit.md](../technical/nuitee-liteapi-audit.md)